New Anatova Ransomware Morphs Itself as an App or Game to Dupe Victims: McAfee

Advertisement
By Tasneem Akolawala | Updated: 24 January 2019 19:01 IST
Highlights
  • Anatova ransomware encrypts files on infected system, then asks for money
  • Most number of users that have been affected are from US
  • Anatova refuses to infect systems in India
New Anatova Ransomware Morphs Itself as an App or Game to Dupe Victims: McAfee

The ransomware seems to have first emerged on January 1

A new ransomware named Anatova has been discovered by McAfee, and the security firm claims that the ransomware disguises itself as free games and software to attract users to download it. This ransomware has hit users mostly in the US, but it's been spotted in Belgium, Germany, France, the UK, and other European countries as well. McAfee claims that the new code behind this ransomware, and its modular extension abilities, suggests that seasoned malware developers are behind this, and it seems to have first emerged on January 1.

The new Anatova ransomware family was discovered in a private peer-to-peer (p2p) network, and McAfee feels that it can become a serious threat since the code is prepared for modular extension. The research company notes that the main goal of Anatova is to cipher all the files it can before requesting payment from the victim.

The ransomware morphs itself into the icon of a game or application to try and fool the user into downloading it. Once downloaded, Anatova will encrypt all or many files on the infected system and insist on payment to unlock them. "The malware developers demand a ransom payment in cryptocurrency of 10 Dash - currently valued at around $700 USD, a quite high amount compared to other ransomware families," the company notes.

McAfee says that Anatova creates RSA Pair of Keys using a crypto API that will cipher all strings. This function is the same as in other ransomware families, such as GandCrab or Crysis. It makes sure that the keys that will be used are per user and per execution. It then writes a ransom note that includes the email address and the payment mode.

Advertisement

"Anatova has the potential to become very dangerous with its modular architecture which means that new functionalities can easily be added. The malware is written by experienced authors that have embedded enough functionalities to be sure that typical methods to overcome ransomware will be ineffective," said Christiaan Beek, lead scientist and principle engineer at McAfee, told ZDnet.

The report also states that Anatova will terminate itself if it finds that the victim is a member of the Commonwealth of Independent States - made up of former Soviet nations, including Russia. It will also not infect systems in Syria, Egypt, Morocco, Iraq and India.

Advertisement

While Indian users are safe for now, we recommend all Internet users to download any unofficial games or apps with caution.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Ransomware, Anatova, McAfee
Advertisement

Related Stories

Popular Mobile Brands
  1. Lava Bold N1, Lava Bold N1 Pro India Pricing, Specifications Teased
  2. Noise Buds F1 With Up to 50-Hour Playback Time Debuts at This Price Tag
  3. Honor Pad 10 With Snapdragon 7 Gen 3 SoC, 10,100mAh Battery Launched
  4. Realme GT 7 Series: Launch Date, Expected Price in India and More
  5. Infinix GT 30 Pro 5G India Launch Date, Colours, Key Features Confirmed
  6. Vijay Sales Apple Days Sale Brings Discounts on These iPhone, Mac Models
  7. Xiaomi Pad 7 Ultra With XRING 01 SoC and 12,000mAh Battery Launched
  8. Gadgets 360 With Technical Guruji: Vivo X200 Ultra, HP OmniStudio X, Fortnite's Return and More
  1. Vivo X200 FE Reportedly Listed on BIS, IMDA Certification Websites Ahead of Anticipated Launch in India
  2. Oracle Said to Buy $40 Billion of Nvidia Chips for OpenAI's US Data Center
  3. Trump Threatens 25 Percent Tariffs on Apple If iPhones Not Made in US
  4. iPhone 16 Pro Max, iPhone 15, MacBook Air (M4) and More Get Discounts During Vijay Sales Apple Days Sale
  5. Anthropic CEO Dario Amodei Says AI Models Hallucinate Less Than Humans: Report
  6. UK Government Updates Crypto Reporting Guidelines, Mandates Collection of Crypto Transaction Data
  7. Acer Swift Neo WIth Intel Core Ultra 5, Up to 32GB RAM Launched in India: Price, Specifications
  8. Elden Ring Film Adaptation in the Works at A24 With Alex Garland Set to Direct
  9. Noise Buds F1 TWS Earbuds With IPX5 Rating, Up to 50-Hour Total Playback Time Launched in India
  10. News Media Alliance Issues Statement on Google’s AI Mode, Calls It ‘Definition of Theft’
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.