Fox ransomware – a dangerous file encrypting virus that is spread via unprotected Remote Desktop Service

Fox ransomware is a cryptovirus that was first spotted by security experts at the end of August 2018. The malware is a new variant of the Matrix ransomware which was originally a screen locker and then evolved, bringing newly designed payloads that encrypt files and demand ransom in the digital currency. The new version takes extra measures to make sure that every single file gets encoded by the AES and the RSA encryption algorithms.[1] After a lengthy process, Fox virus appends [hacker's email].[random_ID].FOX extension of each of the files, and then contacts C&C server[2] to obtain ransom note that is placed into each folder on the system. In the #FOX_README#.rtf message, hackers provide three contact addresses and warn that victims have seven days to pay the ransom; otherwise, all data will be lost.
| SUMMARY | |
| Name | Fox ransomware |
| Type | Crypto virus |
| Cipher | AES and the RSA |
| First spotted by | MalwareHunterTeam[3] |
| File extension | [hacker's email].[random_ID].FOX |
| Ransom note | #FOX_README#.rtf |
| Distribution | Breaking through RDS |
| Elimination | Use trusted security software like FortectIntego or SpyHunterCombo Cleaner |
Security researchers report that Fox ransomware is mostly distributed via Remote Desktop Protocol Service. Hackers scan the internet for the IP addresses that are connected to an unprotected RDP, brute-force the password and then inject the malicious payload manually. While the virus cannot be decrypted at the time of the writing, Fox ransomware removal using comprehensive security tools like FortectIntego or SpyHunterCombo Cleaner should not be a problem.
This variant of Fox ransomware has several peculiarities when it comes to communication and file encryption process. Before file encryption is executed, Fox virus contacts Command and Control server used by criminals to display status updates during the process.
Two program windows will open – fox.matrix.dis.exe (Encryption Status Console) and NWIJjgOC.exe (Network Drives Console) that allow Fox ransomware authors to monitor the process in real-time. The malware will then change permissions of each file and use a modified version of Handle.exe to close all open handles.
Fox ransomware renames each file the following way: [hacker's email].[random_ID].FOX. Malware's targets are all personal files, including:
- Databases
- Pictures
- Image files
- Videos
- Audios
- Documents, etc.
After the encryption process is finished, Fox virus ill drop #FOX_README#.rtf file in each folder and also change the wallpaper. While the RTF file is very long, the wallaper states the following:
We are sorry to inform you that:
ALL YOUR FILES WERE ENCRYPTED with AES-128+RSA-2048 algorithms!
Without your personal key and special software data recovery is impossible!
=============================================================
To recover your files please write us to the e-mails:
PabFox@protonmail.com
FoxHelp@cock.lt
FoxHelp@tutanota.com
=============================================================
Please don't worry, we can help you to restore your server to original
state and decrypt all your files quickly and safely!
Please write us and we will help you!
=============================================================
*We recommend you to send your message ON EACH of our 3 emails!
*Additional info you can find in files #FOX_README#.rtf
While hackers state that they can “help” to recover data, security experts[4] highly advise you not to contact them. Cybercriminals can simply ignore you after the payment in digital currency (usually Bitcoin) is processed and might make you the target of future attacks, knowing that you are willing to pay.
Due to such a long-winded process, detecting malware's presence is much easier. Nevertheless, several thousand files might be encrypted by then, and the damage done might be irreversible. Fortunately to those who got backups, the restore process will be smooth, as long as they remove Fox ransomware beforehand.
Those who did not have their data backed up can try using third-party software that might help with file recovery. All the instructions can be found below.

Use strong passwords for Remote Desktop Protocol
Remote Desktop service can help users to connect to their primary device from another one. If this function is turned on (hackers can easily find that out by scanning IP addresses), what bad actors need to connect to your computer remotely is your set password. Unfortunately, many users do not use safe passwords and instead pick easily-guessable ones, like:
- Password
- qwerty
- 1234
- 9876
- 111111, etc.
Hackers have a whole list of such passwords and try to brute-force the RDP when attempting to connect to the victim's machine. Once succeeded, they can then upload malware and disable security measures. Basically, do everything to what they desire.
To protect yourself from such an intrusion, you should set secure passwords and frequently change them. The easiest way to do that is by using password management programs that use a complicated combination of letters and numbers to make sure that your password is impossible to guess.
Additionally, it is a good idea to disable the service when it is not used.
Remove Fox ransomware and then proceed with file recovery
As we already mentioned, there is no official decryption tool available as of now. However, if your computer got infected and your data is encrypted, the first thing you should do is remove Fox ransomware from your computer. To achieve that you should make use of reputable security tools like FortectIntego or SpyHunterCombo Cleaner – these malware removal tools are capable of deleting all traces of the infection automatically. Nevertheless, you can use any security software of your preference.
Do not forget that malware might disable the operation of security tools, making Fox ransomware removal complicated. Safe Mode with Networking launches the PC with only necessary drivers on; therefore, the AV engines should work correctly.
Was this guide helpful?
Be the first to comment