Security News > 2020 > November > Egregor ransomware bombards victims' printers with ransom notes

Egregor ransomware bombards victims' printers with ransom notes
2020-11-18 17:25

The Egregor ransomware uses a novel approach to get a victim's attention after an attack - shoot ransom notes from all available printers.

Ransomware gangs know that many businesses would rather hide a ransomware attack than make it public, including to employees, for fear of the news affecting stock prices and their reputation.

To increase public awareness of the attack and pressure a victim into paying, the Egregor operation is known to repeatedly print ransom notes from all available network and local printers after an attack.

BleepingComputer can confirm that it is not the ransomware executable performing the printing of ransom notes.

Instead, it is believed that the ransomware attackers utilize a script at the end of an attack to print out ransom notes to all available printers.


News URL

https://www.bleepingcomputer.com/news/security/egregor-ransomware-bombards-victims-printers-with-ransom-notes/