Varonis announces strategic partnership with Microsoft to accelerate the secure adoption of Copilot.

Learn more

CyptMix Ransomware Claims to Donate Your Ransom Payment to Charity

Unlike traditional ransomware notes that rely on fear-based tactics, a new ransomware strain called CyptMix preys on your generosity. Part of the ransom note reads: “Your money will be spent...
Michael Buckbee
1 min read
Last updated January 17, 2023

Unlike traditional ransomware notes that rely on fear-based tactics, a new ransomware strain called CyptMix preys on your generosity.

Part of the ransom note reads:

“Your money will be spent for the children charity. So that is mean that You will get a participation in this process too. Many children will receive presents and medical help!

And We trust that you are kind and honest person! Thank You very much! We wish You all the best! Your name will be in the main donors list and will stay in the charity history!”

Not only will they allegedly donate part of the ransom payment to a children’s charity, they also claim that they’ll provide free technical support for three years.

Our thoughts? A cybercriminal’s altruistic inclination is highly unlikely.

Instead, they’re exploiting an often overlooked element in security – human psychology.

According to a SANS paper on the psychology of social engineering, “the ultimate goal of social engineering is to make the victim want to give the attacker the information the attacker needs because doing so will benefit the victim.”

If you decide to pay the ransom,  it’s probably because you need your files decrypted – not because you want to make a charitable donation by way of CyptMix. But there are security experts that encourage you not to pay the ransom. After all, no cybercriminal is obligated to honor his word!

Interested in preventing ransomware?

Security expert and founder of Bleeping Computer Lawrence Abrams recently wrote that “behavior detection is becoming the best way to detect and stop ransomware as signature detections have become easily bypassed.”

Stop ransomware with UBA and if you’re inclined, directly donate to worthy causes.

What should I do now?

Below are three ways you can continue your journey to reduce data risk at your company:

1

Schedule a demo with us to see Varonis in action. We'll personalize the session to your org's data security needs and answer any questions.

2

See a sample of our Data Risk Assessment and learn the risks that could be lingering in your environment. Varonis' DRA is completely free and offers a clear path to automated remediation.

3

Follow us on LinkedIn, YouTube, and X (Twitter) for bite-sized insights on all things data security, including DSPM, threat detection, AI security, and more.

Try Varonis free.

Get a detailed data risk report based on your company’s data.
Deploys in minutes.

Keep reading

Varonis tackles hundreds of use cases, making it the ultimate platform to stop data breaches and ensure compliance.

defend-against-ransomware-with-the-nist-ransomware-profile
Defend Against Ransomware with the NIST Ransomware Profile
Learn about the NIST ransomware profile and how it can help defend against ransomware with Varonis.
threat-update-47-–-ransomware-early-warning:-data-exfiltration
Threat Update 47 – Ransomware Early Warning: Data Exfiltration
Thought ransomware couldn’t get any worse? Ransomware gangs are now stealing victim’s data before unleashing ransomware – forcing victims to pay up or deal with the fallout when attackers post…
threat-update-#14---post-ransomware-recovery
Threat Update #14 - Post-Ransomware Recovery
To stop ransomware, every second counts. But once the threat is contained, the race is on to get back up and running after a ransomware incident. Click to watch Kilian Englert...
with-keranger,-mac-users-are-no-longer-immune-to-ransomware-threats
With KeRanger, Mac Users Are No Longer Immune to Ransomware Threats
Cybercriminals who previously targeted Windows operating systems with ransomware have expanded their customer base to include the Mac OS. Known as KeRanger, it’s the first ransomware variant detected that infects...