Royal Ransomware: Inside a targeted attack

แชร์
ฝัง
  • เผยแพร่เมื่อ 15 ธ.ค. 2024

ความคิดเห็น • 53

  • @defnotatroll
    @defnotatroll ปีที่แล้ว +74

    That ransom note is hilarious. Imagine reading that troll note while panicking and sweating profusely over losing your data

  • @mancroft
    @mancroft ปีที่แล้ว +43

    In the UK, it is illegal to use the word 'royal' in business without permission. Orf wif their heds!

    • @wannabedal-adx458
      @wannabedal-adx458 ปีที่แล้ว +5

      To the digital tower of London for them!!! :D

    • @arsantiqua2483
      @arsantiqua2483 ปีที่แล้ว

      Do they come for your PC if you dare to slot in some Royal Tridents? Well not that I never put a PC in a cage. We do have rats as pets. Every self-respecting rat will sooner or later brake out and pay the kitchen a visit. But I have never seen a PC break out at night to go raid the breadbasket or someone else's cables. I am still waiting for Wireshark to finally include a rat monitor to detect four legged intruders trying to come for our systems though.

    • @izzycrybaby1164
      @izzycrybaby1164 ปีที่แล้ว

      So if I showed up with a bottle of Crown Royal, would it be confiscated?

    • @mancroft
      @mancroft ปีที่แล้ว

      @@izzycrybaby1164 Straight to the Tower of London.

  • @walid6329
    @walid6329 ปีที่แล้ว +1

    my little brother's laptop got hit by a ransomware, as a punishment I removed his ram so he can't start it and kept it like that

  • @imaweiner1293
    @imaweiner1293 ปีที่แล้ว +3

    Some Black-Hats misspell words on purpose. It's often done so that it's harder to for law-enforcement, as you can pin down possible locations simply by how a word is spelled, (e.g. colour or color)

  • @LuiDipop
    @LuiDipop ปีที่แล้ว +4

    Do you have a video where you talk about checking pc for malware? I used one of your vids to remove malware from my PC and did a bunch of virus scans but I'm scared and paranoid that there might still be malware

  • @hstubbs3
    @hstubbs3 ปีที่แล้ว +1

    Woot! Love them Trellix. They the best.

  • @ManashSarma
    @ManashSarma ปีที่แล้ว +8

    Please test the quick heal total security

    • @Tomb_Raider123
      @Tomb_Raider123 ปีที่แล้ว +1

      He already tested it once or twice. Not a good product as there are several AVs even free AV which is way better than Quick Heal.

  • @SamRocher
    @SamRocher ปีที่แล้ว +1

    Your video shows you typing in a path of "Admininstrator", which appears to be an invalid path on your system. Did you need to edit the file again to fix the path, or did you not even need to enter in the path in the first place?

  • @PcHavenYT
    @PcHavenYT ปีที่แล้ว +4

    Wow im surprised that a ransomware got a ransomware

  • @defnotatroll
    @defnotatroll ปีที่แล้ว +8

    How exactly does the attacker get the target to click on the exe? Who clicks on random exes like that?

    • @TheAnaphos
      @TheAnaphos ปีที่แล้ว +2

      Most of the time with these ransomware groups, the TA will be hands on within the network. I.e. The TA will download the payload themselves and execute the payload

    • @Zullfix
      @Zullfix ปีที่แล้ว +1

      There are many incompetent or technologically illiterate employees with permissions they should not have because of laziness or oversight from management. Those are usually the ones at fault for these attacks succeeding.

  • @Abokarla
    @Abokarla ปีที่แล้ว +1

    I wanna ask a question, and it might sound silly since I'm a beginner. How do you run the NX ransomware? Is there any way to do it without having the code and password?

  • @MohammadRaffliFirmansyah
    @MohammadRaffliFirmansyah 10 หลายเดือนก่อน

    Hello,
    Have you heard about Royal ransomware's successor (Black Suit ransomware)?
    I read from some sources, they said royal and Black Suit is very similar. So I imagine there might be a similar way to make both execute well (successfully encrypt files).
    I have tried several times to execute the black suit ransomware, but none of the attempts were successful (nothing happened). Maybe you know something about how to make black suit ransomware work, please let me know. I need it as part of a final project I'm working on. I would really appreciate any help from you.
    Thanks

  • @mooselexus
    @mooselexus ปีที่แล้ว +1

    Salutations/Greetings,
    Does Acronis offer a free ransomware tool like Kaspersky:)?

  • @galenklassen8634
    @galenklassen8634 ปีที่แล้ว +2

    Great video as usual

  • @Wayne-Jones
    @Wayne-Jones ปีที่แล้ว +3

    If your files are encrypted, is there software or a way to decrypt your files?

    • @njpme
      @njpme ปีที่แล้ว +2

      It depends on the ransomware

    • @tablettablete186
      @tablettablete186 ปีที่แล้ว +1

      I think the problem is not about having a program that decrypts, but the encryption key...

  • @paxfidem2122
    @paxfidem2122 ปีที่แล้ว +1

    Please help, I have been inflicted with DJVU Ransomware

    • @Richard37539
      @Richard37539 ปีที่แล้ว

      I got referred to Nordcybertech for the decryption key online purchase

  • @Ghaz013
    @Ghaz013 ปีที่แล้ว +8

    The broken English in read me file is highly intentional.

    • @defnotatroll
      @defnotatroll ปีที่แล้ว +1

      What's the purpose?

    • @OmniPhantom
      @OmniPhantom ปีที่แล้ว +1

      @@defnotatroll to make it look like they don’t know English, commonly done by people in the united states to make it seem like it is a sample from another country 😊

    • @defnotatroll
      @defnotatroll ปีที่แล้ว

      @@OmniPhantom thanks, but what difference does it make whether the person is from the US or not?

    • @Naaka_311
      @Naaka_311 ปีที่แล้ว +1

      ​@@defnotatroll confuse people where to look for them

  • @SissySara113
    @SissySara113 7 หลายเดือนก่อน

    in a perfect world.
    Security wouldn't be a job. :/

  • @guilherme5094
    @guilherme5094 ปีที่แล้ว

    👍Thanks.

  • @nature-wx6mq
    @nature-wx6mq ปีที่แล้ว

    Sir how to see in your device by sending trojan (rat) in a
    AND
    Sir Ransomware attack encrypts the files so how to decrypt the files Send the video and link I am your subscribervictim's device

  • @wissy006
    @wissy006 ปีที่แล้ว

    Awesome vid thanks leo :D

  • @cydev07
    @cydev07 ปีที่แล้ว +1

    did u talk about redline stealer? the weird thing that everyone can use it and publish his own lol, I'm sure there is more than +500M victims or much

  • @xpower7125
    @xpower7125 ปีที่แล้ว

    these guys should start creating ads

  • @jerryabramson7428
    @jerryabramson7428 ปีที่แล้ว +1

    Nothing bothers me more than a sponsor who doesn’t honor the coupon codes you provide on the channel: The given code is either not valid for the items in the shopping cart or does not exist.
    Please check!

    • @pcsecuritychannel
      @pcsecuritychannel  ปีที่แล้ว

      Sometimes there’s a large time gap between videos so it is possible it is a limited time coupon. I will double check such details for videos in the future to avoid confusion.

  • @vickz2985
    @vickz2985 ปีที่แล้ว +1

    hii

  • @xpower7125
    @xpower7125 ปีที่แล้ว

    wasn't batch for script kiddies .D

  • @chosenuwu
    @chosenuwu ปีที่แล้ว

    that was really interesting :3

  • @linuxyamada8140
    @linuxyamada8140 5 หลายเดือนก่อน

    EZ

  • @frat8853
    @frat8853 ปีที่แล้ว

    This dude is so obsessed with English grammar 😂

  • @cadenh5326
    @cadenh5326 ปีที่แล้ว +2

    Do you know anything about ransomware that encrypts files in an encryption ending with .yajadbv? My workplace was hit with it last week.

    • @pcsecuritychannel
      @pcsecuritychannel  ปีที่แล้ว +1

      th-cam.com/video/k5MOPVRXAeo/w-d-xo.html Watch this video.

    • @mellowtones1985
      @mellowtones1985 ปีที่แล้ว +1

      I hope you guys have an incident response plan in place and backups to recover from.

    • @frdsg8350
      @frdsg8350 ปีที่แล้ว

      ​@@pcsecuritychannelis this link infected with ransomware?

  • @nietzscheshorse7713
    @nietzscheshorse7713 ปีที่แล้ว

    Swe?