• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • New MindLost ransomware requires the use of a credit/debit card to pay a ransom
  • Malware

New MindLost ransomware requires the use of a credit/debit card to pay a ransom

Ddos February 2, 2018 3 minutes read
MindLost ransomware

Security researchers have discovered a new ransomware that encrypts victim files and redirects victims to an online page. Most particularly, it requires that victims pay ransom payments via credit or debit card.

Ransomware is not currently actively distributed and seems to be under development. Security researcher MalwareHunter found the first samples on January 15.

Ransomware identifies itself as MindLost, but Microsoft detects it as Paggalangrypt. It targets a small number of files (such as c, jpg, mp3, mp4, pdf, png, py, and txt) that use specific extensions that will scan all the files stored on the device except the three folders: Windows, Program Files and Program Files (x86).

The biggest clue that MindLost is still developing is that it consumes a lot of time for scanning files, but ends up encrypting only the files in the “C: \ Users” folder.

All encrypted files will be appended with a new .enc extension, such as a file named image.png that, when encrypted, will be renamed image.png.enc.

Once encryption is complete, MindLost downloads a remote image from the remote server containing the instructions for recovering the file and sets it up as the computer’s new desktop wallpaper.

For persistence, MindLost also sets a registry key to ensure that its executable can be run each time the computer restarts.

The information in the picture shows that the victim needs to visit a designated web page to purchase the decryptor for recovering the file.

 

The incredible thing is that MindLost does not require payment through Bitcoin, but instead requires the victim to use a credit or debit card. However, this will inevitably cause MindLost’s operations team to abandon its anonymity.

Researchers think one of the reasons why they do this may be to convince victims to enter the details of payment cards on their Web site and sell them to other hackers. Another reason may be that the payment module is not yet complete, but templates copied from elsewhere are likely to be replaced in future releases.

In addition, the researchers said there are a number of errors in MindLost’s encoding. For example, a person’s name (Hi Daniel Ohayon!) Is included in the binary file path. Although this may be a false reminder aimed at letting investigators go the wrong way, it is not the only error that exists.

According to MalwareHunter, there are currently only four MindLost samples detected on VirusTotal, and all seem to be in development. However, if it enters active distribution, the victim should carefully consider the details of the payment card before entering it. Because the victim may suffer second damage because of payment card details leaked.

Source: bleepingcomputer

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. 50,000 Minecraft players are infected with a malicious program
  2. Malware Hiding in PDFs: What You Need to Know
  3. MutantBedrog: The Malvertiser Bypassing Trusted-Types and CSP with Disruptive Forced Redirect Campaigns
  4. RansomHub’s EDR-Killer: How Zerologon and EDRKillShifter Exploit Networks Without Detection
  5. New XELERA Ransomware Campaign Spreading Through Malicious Documents
Tags: MindLost ransomware

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
  • CVE-2026-9435CVSS 9.8
    A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9434CVSS 9.8
    A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is...
  • CVE-2026-9433CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-2651CVSS 9.0
    A vulnerability in MLflow versions
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity © All rights reserved.