Caution: This new ransomware in India makes your ornate new clothes
New Delhi, May 23: A new ransomware has been detected in India that makes victims donate new clothes to homeless, feed kids in branded pizza outlets and provide financial help to anyone who needs urgent medical attention but cannot afford it, according to digital risk monitoring firm Cloudsek. The company warned that the Goodwill ransomware could also result in temporary, and possibly permanent, loss of company data and a possible shutdown of the company's operations and accompanied revenue loss.

"GoodWill ransomware was identified by CloudSEK researchers in March 2022. As the threat group's name suggests, the operators are allegedly interested in promoting social justice rather than conventional financial reasons," Clousek said in a report.
Once infected, the GoodWill ransomware worm encrypts documents, photos, videos, database, and other important files and renders them inaccessible without the decryption key.
The actors suggest that victims perform three socially driven activities in exchange for the decryption key- donate new clothes to the homeless, record the action, and post it on social media, take five less fortunate children to Dominos Pizza Hut or KFC for a treat, take pictures and videos, and post them on social media and provide financial assistance to anyone who needs urgent medical attention but cannot afford it, at a nearby hospital, record audio, and share it with the operators," the report said.
Once all three activities are completed, the ransomware asks victims to write a note on social media (Facebook or Instagram) on "how you transformed yourself into a kind human being by becoming a victim of a ransomware called GoodWill." Upon completing all three activities, the ransomware operators verify the media files shared by the victim and their posts on social media.
The actor will then share the complete decryption kit which includes the main decryption tool, password file and a video tutorial on how to recover all important files, the report said.
"Our researchers were able to trace the email address, provided by the ransomware group, back to an India-based IT security solutions & services company, that provides end-to-end managed security services," the report said.
(PTI)
-
Gold Silver Rate Today, 9 March 2026: City-Wise Prices, MCX Gold and Silver Ease Slightly After Rally -
Chinese Spy Ship Liaowang-1 Spotted Near Oman: Why Its Presence Near Oman Is Concerning For US Military -
Pune Gold Rate Today: Check Gold Prices For 18K, 22K, 24K in Pune -
Bangalore Gold Silver Rate Today, March 9, 2026: Gold and Silver Prices Fall as US Dollar Strengthens -
Who Is Nishant Kumar: Education, Personal Life and Possible Political Role -
Ind Vs NZ T20 World Cup Phalodi Satta Bazar Prediction: Know Who Will Win In India vs New Zealand Final -
Vijay-NDA Alliance On Cards? Pawan Kalyan Reportedly Reaches Out to TVK Chief -
Who Was Mojtaba Khamenei’s Wife Zahra Haddad-Adel and What Do We Know About Her? -
Trisha Hits Back at Parthiban: 'Crude Words Say More About the Speaker' -
India vs New Zealand T20 World Cup 2026 Final: Five Positive Signs Favouring India Before Title Clash -
IND vs NZ Final Live: When and Where to Watch India vs New Zealand T20 World Cup 2026 Title Clash -
Ind vs NZ T20 World Cup 2026: New Zealand Needs 256 Runs To Beat India And Win The World Cup












Click it and Unblock the Notifications