Skip to main content
Skip to main content
Published Apr 23, 2020 | Updated Jul 13, 2020

Ransom:Java/Lanifynop

Detected by Microsoft Defender Antivirus

Aliases: PonyFinal (Ikarus)

Summary

This ransomware encrypts files to prevent users from accessing their data or their computer. It might ask for payment to restore access to the encrypted data.

This ransomware has been delivered as a payload in human-operated ransomware campaigns, where human attackers directly take part in breaches to deploy ransomware. Attackers can use a mix of deployment methods like Windows Management Instrumentation (WMI) or the PsExec command-line. However, there have been cases where attackers utilize software distribution servers to deploy this ransomware.

To get more details and learn how to protect against ransomware, read:  

There is no one-size-fits-all response if you have been victimized by ransomware. To recover files, you can restore backups. There is no guarantee that paying the ransom will give you access to your files. See our ransomware page for help on what to do in response to a ransomware infection.

Get more help

If you are unable to remove this malware, see our advanced troubleshooting page for more help. You can also search the Microsoft virus and malware community for relevant information.

Follow us