
Researchers have discovered āAnatova,ā a brand new family of cryptocurrency-fuelled ransomware, and they warn it has the potential to become outright dangerous.
Cybersecurity firm McAfee explained Anatova hides in seemingly innocuous icon files ā usually the same popular games or applications ā in order to fool the user into downloading the malware.
Once run, it automatically requests admin rights and begins encrypting as many files as possible, as quickly as possible. Anatova then demands a ransom from the victim.
In this case, the hackers want payment in fledgling cryptocurrency DASH ā currently worth around $700.
Analysts also revealed they had detected over 100 instances of the Anatova running in the US already. Belgium, Germany, and France are also hosting a sizable number of infections.

āAnatova has the potential to become very dangerous with its modular architecture which means that new functionalities can easily be added,ā McAfeeās lead scientist Christiaan Beek told Hard Fork.
While hackers demanding DASH ransoms may be less common than ransoms in Bitcoin or Monero, it isnāt exactly unprecedented.
In fact, the GandCrab ransomware family, first discovered in early 2018, was reportedly the first of its kind to demand DASH payments.
āThe main reason [Anatova is] using DASH is that it has implemented a number of privacy enhancing protocols that make tracing transactions difficult,ā Christiaan added.
Anatova ransomware is more sophisticated than Ryuk
Not that long ago, Hard Fork reported on a malware threat sweeping the internet known as Ryuk. At the time, estimates suggested it had collected more than $3.7 million in Bitcoin ransoms in just five months.
Ominously, McAfeeās researchers believe the hackers responsible for Anatovaās creation are more skilled than Ryukās creators.
āAnatova has, in our opinion, a more advanced design than Ryuk,ā said Christiaan. āSpecifically, in the way it tries to make analysis difficult and the way the actors try to avoid the creation of a decryption-tool, but also in the way it is designed to encrypt fast ā only files below 1MB are encrypted.ā

Unlike Ryuk, which hackers derived from source-code available for sale on underground markets, Christiaan believes Anatova was designed by someone with coding expertise.
āThe malware is written by experienced authors that have embedded enough functionalities to be sure that typical methods to overcome ransomware will be ineffective, for instance data canāt be restored without payment and a generic decryption-tool cannot be created,ā he noted.
If all this makes you a bit nervous, here is a handy guide on how to best protect yourself against these kinds of ransomware threats, because youāre worth it.
Get the TNW newsletter
Get the most important tech news in your inbox each week.