SplinterJoke Ransomware encrypts user files and data and asks them to contact them for the decryption key. After encryption, it changes the wallpaper of the system saying that this ransomware is a Proof of Concept (POC) for SentinelOne.
XFSADM has been detected that as ATM malware but its author's identification or intentions are not clear. It was first detected in Russia in 2019.
Ducky Ransomware encrypts user data and asks them to contact the attacked on Telegram handle duckydecrypt or contact them at ballxball@protonmail.com in 48 hours.
DEADWOOD Wiper take place of the Apostle Wiper, which has many logical flaws and it did not work as expected by the attackers named as Agrius. Agrius also utilized DEADWOOD (aka Detbosit), a wiper. It is written in C++ using the Boost libraries.
Apostle is a .NET based malware that evolves from a Wiper to full-featured ransomware. It shares code with another tool from Agris APT arsenal, IPsec Helper.