Ducky Ransomware encrypts user data and asks them to contact the attacked on Telegram handle duckydecrypt or contact them at ballxball@protonmail.com in 48 hours.
DEADWOOD Wiper take place of the Apostle Wiper, which has many logical flaws and it did not work as expected by the attackers named as Agrius. Agrius also utilized DEADWOOD (aka Detbosit), a wiper. It is written in C++ using the Boost libraries.
Apostle is a .NET based malware that evolves from a Wiper to full-featured ransomware. It shares code with another tool from Agris APT arsenal, IPsec Helper.
IPsec Helper is a backdoor implant used by Agrius APT. Agrius is attributed to Iran and allegedly targets Israeli systems. IPsec Helper is written in .net and provides many services to its owner.
The Commonwealth of Independent States (CIS) is formed after the collapse of former Soviet Union in 1991. is a regional intergovernmental organization of nine members, plus two founding non-member, post-Soviet republics in Eurasia.