Ransomware related to VanHelsing RaaS. Written in C++, it accepts several command line arguments that control the encryption process, such as whether to encrypt network and local drives or specific directories and files. VanHelsing was recently leaked, the software itself cost $10,000.
Features
Cross-platform: Attacks Windows, Linux, BSD, ARM, VMware ESXi (only confirmed cases on Windows). Encryption: Uses ChaCha20 and Curve25519, partial encryption for large files, .vanhelsing extension.
Double blackmail: Encrypts files and threatens to leak data.
Stealth: "Silent" mode, delete shadow copies, change wallpaper, flexible settings via command line.
download:
Features
Cross-platform: Attacks Windows, Linux, BSD, ARM, VMware ESXi (only confirmed cases on Windows). Encryption: Uses ChaCha20 and Curve25519, partial encryption for large files, .vanhelsing extension.
Double blackmail: Encrypts files and threatens to leak data.
Stealth: "Silent" mode, delete shadow copies, change wallpaper, flexible settings via command line.
download: