• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Credit: Franz Bachinger/Pixabay

    Attackers Targeting LLMs in Widespread Campaign

    TCE-Exclusive-interview-with-Dr-Amit-Chaubey

    Inside the 2026 Business Blast Radius: Dr. Amit Chaubey on Why Cyber Disruption Is Now a Sovereign Risk

    Internet Blackout, Iran, Trump, Civil Unrest, Internet Shutdown

    84 Hrs and Counting as Internet Blackout in Iran Continues Amid Nationwide Unrest

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Kyowon Group cyberattack

    Kyowon Group Confirms Cyberattack as Multiple Systems Go Offline

    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Canopy Health data breach

    Canopy Health Confirms Cyberattack, Patients Not Notified for Six Months

    North Korean Kimsuky Threat Actors Use Malicious QR Codes and Quishing to Target Foreign Policy Experts

    North Korean Kimsuky Threat Actors Use Malicious QR Codes to Target Foreign Policy Experts

    cybersecurity news The Cyber Express

    The Cyber Express Weekly Roundup: Schools, Hacktivists, and National Cyber Overhauls

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Government Cyber Action Plan

    UK Moves to Close Public Sector Cyber Gaps With Government Cyber Action Plan

    Donald_Trump

    Trump Orders US Exit from Global Cyber and Hybrid Threat Coalitions

    Cyber action plan, UK, cyber threats targeting political candidates

    UK Unveils £210M Cyber Overhaul as Nation Faces “Critically High” Digital Threat

    MongoBleed, MongoDB, CVE-2025-14847

    Critical ‘MongoBleed’ Flaw Exploited in the Wild to Leak Database Secrets

    DPDP Act Is Reshaping the Cyber Insurance Landscape

    Beyond Compliance: How India’s DPDP Act Is Reshaping the Cyber Insurance Landscape

    FBI Seizes E-Note Crypto Exchange

    FBI Seizes E-Note Crypto Exchange Linked to Ransomware Money Laundering

    DPDP Act

    8 Ways the DPDP Act Will Change How Indian Companies Handle Data in 2026 

    FBI Warns

    FBI Cautions Alaskans Against Phone Scams Using Fake Arrest Threats

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

    Third-Party Risk Management in Healthcare

    Why Healthcare CISOs Must Prioritize Third-Party Risk Management

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    ARC Data Sale

    ARC Data Sale Scandal: Airlines’ Travel Records Used for Warrantless Surveillance

    NYT, ChatGPT, The New York Times, Voice Mode, OpenAI Voice Mode

    OpenAI Battles Court Order to Indefinitely Retain User Chat Data in NYT Copyright Dispute

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Credit: Franz Bachinger/Pixabay

    Attackers Targeting LLMs in Widespread Campaign

    TCE-Exclusive-interview-with-Dr-Amit-Chaubey

    Inside the 2026 Business Blast Radius: Dr. Amit Chaubey on Why Cyber Disruption Is Now a Sovereign Risk

    Internet Blackout, Iran, Trump, Civil Unrest, Internet Shutdown

    84 Hrs and Counting as Internet Blackout in Iran Continues Amid Nationwide Unrest

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Kyowon Group cyberattack

    Kyowon Group Confirms Cyberattack as Multiple Systems Go Offline

    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Canopy Health data breach

    Canopy Health Confirms Cyberattack, Patients Not Notified for Six Months

    North Korean Kimsuky Threat Actors Use Malicious QR Codes and Quishing to Target Foreign Policy Experts

    North Korean Kimsuky Threat Actors Use Malicious QR Codes to Target Foreign Policy Experts

    cybersecurity news The Cyber Express

    The Cyber Express Weekly Roundup: Schools, Hacktivists, and National Cyber Overhauls

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Government Cyber Action Plan

    UK Moves to Close Public Sector Cyber Gaps With Government Cyber Action Plan

    Donald_Trump

    Trump Orders US Exit from Global Cyber and Hybrid Threat Coalitions

    Cyber action plan, UK, cyber threats targeting political candidates

    UK Unveils £210M Cyber Overhaul as Nation Faces “Critically High” Digital Threat

    MongoBleed, MongoDB, CVE-2025-14847

    Critical ‘MongoBleed’ Flaw Exploited in the Wild to Leak Database Secrets

    DPDP Act Is Reshaping the Cyber Insurance Landscape

    Beyond Compliance: How India’s DPDP Act Is Reshaping the Cyber Insurance Landscape

    FBI Seizes E-Note Crypto Exchange

    FBI Seizes E-Note Crypto Exchange Linked to Ransomware Money Laundering

    DPDP Act

    8 Ways the DPDP Act Will Change How Indian Companies Handle Data in 2026 

    FBI Warns

    FBI Cautions Alaskans Against Phone Scams Using Fake Arrest Threats

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

    Third-Party Risk Management in Healthcare

    Why Healthcare CISOs Must Prioritize Third-Party Risk Management

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    ARC Data Sale

    ARC Data Sale Scandal: Airlines’ Travel Records Used for Warrantless Surveillance

    NYT, ChatGPT, The New York Times, Voice Mode, OpenAI Voice Mode

    OpenAI Battles Court Order to Indefinitely Retain User Chat Data in NYT Copyright Dispute

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Cyble Research and Intelligence Labs Uncovers Novel ‘Kanti’ Ransomware Targeting Cryptocurrency Users

The cybercriminals behind Kanti specifically focus on cryptocurrency users, particularly those associated with Bitcoin (BTC) wallets.

thecyberexpress by thecyberexpress
July 20, 2023
in Firewall Daily, Ransomware News
0
Kanti ransomware
660
SHARES
3.7k
VIEWS
Share on LinkedInShare on Twitter

Cyble Research and Intelligence Labs (CRIL) recently discovered a new strain of ransomware dubbed “Kanti” that poses a significant threat to cryptocurrency users.

The Kanti ransomware earned its name due to its distinct encryption method, appending the “.kanti” extension to encrypted files, and dropping a ransom note called “Kanti.html” after the encryption process is completed.

The cybercriminals behind Kanti specifically focus on cryptocurrency users, particularly those associated with Bitcoin (BTC) wallets.

Cyble researchers found that Kanti ransomware is built using the NIM programming language, which is relatively new and known for its efficient execution and cross-platform compatibility.

“Previously, the Dark Power ransomware group utilized the NIM programming language to create ransomware variants that can encrypt victims’ files while deliberately excluding critical system files,” said the CRIL report.

Moreover, the malware possessed the capability to clear logs and generate a ransom note within each infected folder.

report-ad-banner

NIM’s unique features enable malware authors to create ransomware that targets both Windows and Linux operating systems, making it a versatile tool for cybercriminals seeking to evade detection.

Kanti Ransomware: Execution and encryption process

Kanti is a new type of ransomware that targets people who use cryptocurrency, especially Bitcoin. It’s a malicious software designed to lock up your files and demand a ransom from you to get them back.

The attackers distribute the ransomware through a file named “BTC Wallet.zip.” Inside this compressed file, there are two other files: “Open Private Keys For Access To Wallet.lnk” and “Locked_253_BTC.zip.

When you open the “Open Private Keys For Access To Wallet.lnk” file, it actually runs the “Locked_253_BTC.zip” file. The “lnk” file is made to look harmless, but it’s the actual ransomware in disguise.

Once you run the ransomware, it starts encrypting your files. Encryption is like putting a lock on your files so that you can’t access them without a special key. In this case, the attackers have the key, and they demand money (ransom) to give it to you.

Kanti ransomware scans the system volumes using API functions to identify files and directories for encryption.

Interestingly, the ransomware selectively excludes certain files and folders from encryption, ensuring critical system files and components necessary for the proper functioning of the victim’s system remain unaffected.

Kanti ransomware is cleverly programmed to avoid encrypting certain important files that are necessary for your computer to function properly. This ensures that the computer remains operational, and you can still use it to pay the ransom.

The ransomware is created using a new programming language called NIM. This language allows the attackers to make the ransomware work on both Windows and Linux computers.

To lock your files securely, the ransomware uses a special module called “BCrypt.dll.” This module generates the encryption keys that are needed to lock and unlock your files.

After your files are encrypted, the ransomware leaves a message called “Kanti.html” on your Desktop. This message explains that your files are locked, and it provides instructions on how to pay the ransom to get the decryption key.

To cover its tracks, the ransomware deletes itself from your computer after encrypting your files. It also displays the ransom note before exiting, so you know what happened.

Kanti ransomware: Effects and precautions

Like all other ransomware strains, the main impact of impact of Kanti is the loss of valuable data.

Falling victim to a ransomware attack hits an organization’s reputation and integrity badly, leading to a loss of trust from customers and partners.

Ransomware can expose sensitive business information, posing a serious risk to the confidentiality of its consumers, affiliates, and stakeholders.

The disruptive nature of ransomware is another major concern.

Once infected, computers or networks may become inoperable until the ransom is paid or the situation is resolved, causing significant disruptions to regular operations.

Regularly backing up important data is essential, recommend Cyble researchers.

Keeping backups offline or on separate networks ensures that a safe copy of the data is available for recovery if needed.

Enabling automatic software updates on computers, mobile devices, and other connected devices helps to keep security vulnerabilities in check and devices protected against known threats, the researchers added.

Share this:

  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on X (Opens in new window) X
  • Click to share on Facebook (Opens in new window) Facebook
  • More
  • Click to email a link to a friend (Opens in new window) Email
  • Click to share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: Kanti Ransomware
Previous Post

Birmingham Airport Cyber Attack: Indicator of Escalating Threats to Aviation Sector

Next Post

WhatsApp Outage Impacts Over 200,000 Users, ‘Under Control’ Says Company

Next Post
WhatsApp Outage

WhatsApp Outage Impacts Over 200,000 Users, 'Under Control' Says Company

Threat Landscape Reports 2025

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

Credit: Franz Bachinger/Pixabay
Cyber News

Attackers Targeting LLMs in Widespread Campaign

January 12, 2026
TCE-Exclusive-interview-with-Dr-Amit-Chaubey
Cyber News

Inside the 2026 Business Blast Radius: Dr. Amit Chaubey on Why Cyber Disruption Is Now a Sovereign Risk

January 12, 2026
Internet Blackout, Iran, Trump, Civil Unrest, Internet Shutdown
Cyber News

84 Hrs and Counting as Internet Blackout in Iran Continues Amid Nationwide Unrest

January 12, 2026
National Security Agency (NSA) appointment
Business News

NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

January 12, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information