Bitcoin Ransomware Education – XData

It looks like the ransomware threat is only becoming more prominent over time. XData, a recently discovered type of malicious software, is causing a lot of problems in the Ukraine. Hundreds of computers have been infected successfully, and a lot of the victims were forced to pay the ransom. It is evident to the people behind this ransomware strain are trying to make their presence known.

Number of XData Infections Grows Exponentially

Security researchers all over the world are growing concerned over what the XData ransomware strain represents. To be more specific, the malicious software was spotted earlier this week. However, it seems the developers and distributors are upping their game. The number of successful infections across the Ukraine is four times higher compared to WannaCry. That is quite an amazing – and troublesome – feat.

To be more specific, no one knows for sure why this type of malicious software is growing so omnipresent all of a sudden. Considering how the Ukraine was the fifth-most affected target of WannaCry ransomware, it is remarkable XData infected four times as many computers. What is even stranger is how the software did so in such a short amount of time. This goes to show computers in this country have a serious security issue.

As if that isn’t enough to worry about, it appears XData is the second–most distributed ransomware over the past 24 hours. It is only marginally behind Cerber, which remains a very real threat that needs to be addressed sooner or later. It also appears the ransomware is now spreading to neighboring countries, as incidents have been reported across Russia, Germany, and Estonia. This is not a positive development by any means, though.

Related Post

Similar to a lot of other ransomware types, XData uses AES encryption and renames file extensions to something more custom. As part of its encryption process, XData goes after local files and unmapped network shares. This type of behavior has become more prevalent among malicious software types as of late. Criminals want to cause as much damage as possible, after all.

Moreover, anyone infected with XData will need to contact the developers via email before they receive payment instructions. This type of behavior has also become quite popular as of late. Criminals no longer link Tor-based URLs for the payment page, but rather prefer to do things via email. This also means we have no idea how big the ransom is for the victims, although it is possible the number is somewhere close to the $250 range.

For the time being, getting rid of XData ransomware without paying the ransom or restoring files from a backup is virtually impossible. Security experts are analyzing the ransomware sample they obtained to reverse-engineer the software, but that process can take quite some time. It will be interesting to see if XData makes its way to other countries in the future, although it seems likely that will happen sooner or later.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Vitalik Buterin Deploys 16,384 ETH Toward Privacy And Open Infrastructure

Ethereum co-founder Vitalik Buterin is once again channeling personal capital into the long-term foundations of…

15 hours ago

Lido V3 Launches on Ethereum Mainnet With Game-Changing stVaults

Lido Finance has officially activated Lido V3 on the Ethereum mainnet, introducing a powerful new…

15 hours ago

Bitcoin Slips To $83,500 As Liquidations Rock The Market

Bitcoin tumbled to around $83,500, marking its lowest level in over a month and triggering…

2 days ago

The 190M Daily Squeeze: ZKP’s $1.6M Momentum Ranks It as the Best Presale Crypto for 10,000x Gains

The Zero Knowledge Proof (ZKP) presale auction has officially entered Stage 2, and for anyone…

3 days ago

Ethereum Signals ERC-8004 Mainnet Launch For AI Agents

Ethereum has announced that ERC-8004, a new token standard designed for AI agents, is heading…

3 days ago

Ondo’s Tokenized U.S. Treasuries Go Live on Sei

Tokenized U.S. Treasuries from Ondo Finance are now live on the Sei Network, marking a…

3 days ago