XINOF is a Ransomware-as-a-Service group known for targeting individual users with four encryption methods per file.
Analyst brief
XINOF (also known as Fonix/FonixCrypter) is a Ransomware-as-a-Service (RaaS) group that operated from June 2020. It primarily targeted individual users and small businesses. Its key TTPs included using four different encryption methods per file; however, the group ceased operations in January 2021 and released a universal decryptor for all victims. Defenders should remain vigilant for signs of unauthorized file encryption, especially on legacy and unpatched systems, as remnants of this ransomware may still be encountered.
xinof
crime
XINOF (also known as Fonix/FonixCrypter) is a RaaS operation that began in June 2020 with no upfront affiliate cost and four methods of encryption per file; the operators shut down the service and released the master decryption key in January 2021, allowing free decryption for all victims.