Whenever a threat is “localized” to a specific region, it’s a sign that attackers believe there is money to be made. Ransomware has made millions of dollars around the world, and it looks like it’s poking its nose into a new part of the world: China. However, the initial foray into this market made several mistakes that
We recently came across a sample of what appeared to be Chinese-language ransomware. We detect this as Ransom_SHUJIN.A. All of these samples could be decompressed into the same executable file. While this is not the first time that Chinese-language ransomware has been found, this may be the first time that one used simplified Chinese characters. This character set is favored for use in mainland China.
Post from: Trendlabs Security Intelligence Blog – by Trend Micro