xinof logo

xinof

1 incidentes 0 paises 0 sectores ransomware IR Ultimo: 2026-06-25
Aliases: XINOF R2, Fonix Ransomware, FonixCrypter
Ver en IntelTracker → APTTrail →
Xinof emerged as a variant of Fonix ransomware, first observed in November 2020. This group operates with a clear financial motivation, employing encryption techniques to extort payments from victims. Xinof distinguished itself by appending a unique extension, such as '.XINOF', to encrypted files and by displaying a fake Windows update screen during the encryption process, which also included changing the desktop wallpaper. The group's operation was short-lived, as the developers of Fonix ransomware publicly announced its shutdown in February 2021. The group frequently demanded ransom in Bitcoin, threatening to double the amount if victims failed to establish contact within 48 hours and to delete files if payments were not made. There are no known aliases for Xinof beyond its classification as a Fonix variant, and its operations ceased relatively quickly after its emergence.
Tecnicas MITRE
T1133, T1203, T1490, T1486

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

CanadaIran, Islamic Republic ofRussian FederationUnited States

Sectores objetivo (SOCRadar)

ManufacturingFinanceEducational ServicesHealthCare & Social AssistanceOtherPublic AdministrationBanking

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com