Ransomware Group:  
Rook



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how compromised credentials are impacting your business


Sites | Ransom Note(s) | Activity | Victims (9)

According to PCrisk, Rook is ransomware (an updated variant of Babuk) that prevents victims from accessing/opening files by encrypting them. It also modifies filenames and creates a text file/ransom note (HowToRestoreYourFiles.txt). Rook renames files by appending the .Rook extension. For example, it renames 1.jpg to 1.jpg.Rook, 2.jpg to 2.jpg.Rook.


Sites

Title Available Last Visit FQDN Screenshot
We Are Rook!!! 🔴 2022-01-26 15:24:16.586824 gamol6n6p2p4c3ad7gxmx3ur7wwdwlywebo2azv3vv5qlmjmole2zbyd.onion N/A

Ransom Note(s)

Activity over time

9 Victims

 flag

Abdi ibrahim

Company logo


Discovery Date: 2022-01-08 10:19

Sector:

 flag

Evalueserve

Company logo


Discovery Date: 2021-12-28 02:35

Sector:

 flag

DENSO

Company logo


Discovery Date: 2021-12-28 02:35

Sector:

 flag

Data breach summary

Company logo


Discovery Date: 2021-12-26 13:22

Sector:

 flag

Rossell Techsys(Data will be given tomorrow)

Company logo


Discovery Date: 2021-12-18 16:06

Sector:

 flag

KMG Prestige, Inc. (Data will be given tomorrow)

Company logo


Discovery Date: 2021-12-18 16:06

Sector:

 flag

Rosendahl Design Group

Company logo


Discovery Date: 2021-12-14 14:56

Sector:

 flag

Rossell Techsys

Company logo


Discovery Date: 2021-12-14 13:18

Sector:

 flag

KMG Prestige, Inc.

Company logo


Discovery Date: 2021-12-07 07:01

Sector: