http://ransomlookumjrc6erzqn467lkcu2t5h4enjzfigvsxrrktxicysi2yd.onion/group/bitransomware
Once activated, BitRansomware encrypts files and appends the .ReadMe extension—leaving ransom notes to guide victims toward payment. The campaign peaked sharply around November 4, 2020, with over 28,000 email instances detected in a single day, as seen by VMware NSX telemetry. External Analysis https://blogs.vmware.com/security/2020/12/phorpiex-powered-bitransomware-targets-apac-universities.html Urls Screen File servers Screen Chat servers Screen...