Ransomware Group:  
Rook



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | Ransom Note(s) | Activity | Worldmap | Victims (9)

According to PCrisk, Rook is ransomware (an updated variant of Babuk) that prevents victims from accessing/opening files by encrypting them. It also modifies filenames and creates a text file/ransom note (HowToRestoreYourFiles.txt). Rook renames files by appending the .Rook extension. For example, it renames 1.jpg to 1.jpg.Rook, 2.jpg to 2.jpg.Rook.


Sites

Title Available Last Visit FQDN Screenshot
We Are Rook!!! 🔴 2022-01-26 15:24:16.586824 gamol6n6p2p4c3ad7gxmx3ur7wwdwlywebo2azv3vv5qlmjmole2zbyd.onion N/A

Ransom Note(s)

Activity over time

Worldmap

9 Victims

 flag

Abdi ibrahim 

Company logo
Ransomware Group:

Discovery Date: 2022-01-08 10:19

Sector:

Group: 
 flag

Evalueserve 

Company logo
Ransomware Group:

Discovery Date: 2021-12-28 02:35

Sector:

Group: 
 flag

DENSO 

Company logo
Ransomware Group:

Discovery Date: 2021-12-28 02:35

Sector:

Group: 
 flag

Data breach summary 

Company logo
Ransomware Group:

Discovery Date: 2021-12-26 13:22

Sector:

Group: 
 flag

Rossell Techsys(Data will be given tomorrow) 

Company logo
Ransomware Group:

Discovery Date: 2021-12-18 16:06

Sector:

Group: 
 flag

KMG Prestige, Inc. (Data will be given tomorrow) 

Company logo
Ransomware Group:

Discovery Date: 2021-12-18 16:06

Sector:

Group: 
 flag

Rosendahl Design Group 

Company logo
Ransomware Group:

Discovery Date: 2021-12-14 14:56

Sector:

Group: 
 flag

Rossell Techsys 

Company logo
Ransomware Group:

Discovery Date: 2021-12-14 13:18

Sector:

Group: 
 flag

KMG Prestige, Inc. 

Company logo
Ransomware Group:

Discovery Date: 2021-12-07 07:01

Sector:

Group: