New Anatova Ransomware Morphs Itself as an App or Game to Dupe Victims: McAfee

Advertisement
By Tasneem Akolawala | Updated: 24 January 2019 19:01 IST
Highlights
  • Anatova ransomware encrypts files on infected system, then asks for money
  • Most number of users that have been affected are from US
  • Anatova refuses to infect systems in India

The ransomware seems to have first emerged on January 1

A new ransomware named Anatova has been discovered by McAfee, and the security firm claims that the ransomware disguises itself as free games and software to attract users to download it. This ransomware has hit users mostly in the US, but it's been spotted in Belgium, Germany, France, the UK, and other European countries as well. McAfee claims that the new code behind this ransomware, and its modular extension abilities, suggests that seasoned malware developers are behind this, and it seems to have first emerged on January 1.

The new Anatova ransomware family was discovered in a private peer-to-peer (p2p) network, and McAfee feels that it can become a serious threat since the code is prepared for modular extension. The research company notes that the main goal of Anatova is to cipher all the files it can before requesting payment from the victim.

Advertisement

The ransomware morphs itself into the icon of a game or application to try and fool the user into downloading it. Once downloaded, Anatova will encrypt all or many files on the infected system and insist on payment to unlock them. "The malware developers demand a ransom payment in cryptocurrency of 10 Dash - currently valued at around $700 USD, a quite high amount compared to other ransomware families," the company notes.

McAfee says that Anatova creates RSA Pair of Keys using a crypto API that will cipher all strings. This function is the same as in other ransomware families, such as GandCrab or Crysis. It makes sure that the keys that will be used are per user and per execution. It then writes a ransom note that includes the email address and the payment mode.

Advertisement

"Anatova has the potential to become very dangerous with its modular architecture which means that new functionalities can easily be added. The malware is written by experienced authors that have embedded enough functionalities to be sure that typical methods to overcome ransomware will be ineffective," said Christiaan Beek, lead scientist and principle engineer at McAfee, told ZDnet.

The report also states that Anatova will terminate itself if it finds that the victim is a member of the Commonwealth of Independent States - made up of former Soviet nations, including Russia. It will also not infect systems in Syria, Egypt, Morocco, Iraq and India.

Advertisement

While Indian users are safe for now, we recommend all Internet users to download any unofficial games or apps with caution.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Ransomware, Anatova, McAfee
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy A37 vs Poco X8 Pro Max vs Vivo V70: Which Is a Better Handset
  2. Xiaomi 17 Review: Small Flagship, Big Price Tag
  1. Scientists Trace Solar Storm Origins to Hidden Layer Deep Inside the Sun
  2. Panchhi 2 OTT Release: When and Where to Watch Prince Kanwaljit Singh’s Thriller Online
  3. Khakee Circus Brings a Fun Cop vs Thief Chase to ZEE5 This April
  4. Five Nights at Freddy’s 2 Now Streaming on OTT: What You Need to Know
  5. Hubble Telescope Captures Comet Reversing Its Rotation for the First Time
  6. Sony Raises PlayStation 5, PlayStation 5 Pro and PlayStation Portal Prices Globally
  7. Wikipedia Says No to AI-Generated Text in Articles, but Makes Two Exceptions
  8. Oppo Find X9 Ultra Teased to Feature 10x Telephoto Camera With Advanced Stabilisation
  9. Japan’s FSA Warns KuCoin Over Unregistered OTC Derivatives Trading
  10. OnePlus Nord CE 6, Nord CE 6 Lite Tipped to Launch in India; Fresh Leaks Reveal Nord CE 6 Lite Features, Design
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.