Hackers Cover Ransomware via New NSIS Installers

Опубликовано: 16 Июль 2026
на канале: Virus Guides
695
6

Microsoft reported that new distribution campaigns are using installer files from the Nullsoft Scriptable Install System (NSIS) to evade ransomware.

Not long ago, the NSIS installers were associated with different ransomware families, such as Locky, Cerber, Critroni (aka CTB-Locker), Crowti (aka CryptoWall), Wadhrama, and Teerac (aka Crypt0L0cker).

What the new NSIS installers do is trying to evade anti-virus detection by incorporating non-malicious components.