{
  "family": "recory",
  "sample_count": 1,
  "category": "ransomware",
  "description": "<h3>Executive Summary</h3>\nRecory is a deceptive malware family that operates primarily as \"Scareware\" or a Fake Antivirus (Fake AV) program, while occasionally exhibiting aggressive ransomware-like behaviors. Its core objective is financial extortion. It infiltrates a system, generates fabricated security alerts claiming the machine is heavily infected, and demands immediate payment (usually via credit card) for a \"premium license\" to remove the non-existent threats.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nRecory is most commonly distributed via aggressive \"malvertising\" campaigns (where malicious ads redirect users to pages claiming their PC is infected) or bundled within \"free\" software installers downloaded from untrustworthy sources.\n\nOnce executed, Recory focuses entirely on psychological manipulation and system disruption:\n<ul>\n<li><strong>Fabricated Scans and Alerts:</strong> The malware launches a highly realistic, but completely fake, graphical user interface mimicking legitimate antivirus software (e.g., Windows Defender). It performs a rapid \"scan\" and invariably reports dozens of critical infections, utilizing flashing red warnings and alarming sound effects.</li>\n<li><strong>System Disruption (Ransomware Behavior):</strong> To force the user to pay, Recory actively disrupts normal system operations. It frequently terminates legitimate executable files (like Task Manager, Registry Editor, and real antivirus software), claiming they are \"infected.\" Some aggressive variants will hide desktop icons and the taskbar, simulating a locked system.</li>\n<li><strong>Extortion Portal:</strong> The malware constantly redirects the user's web browser to a payment portal controlled by the attackers, demanding a credit card payment to \"activate\" the fake antivirus and restore the system.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nWhile Recory typically does not utilize strong encryption to lock files (like true ransomware), it causes massive operational disruption and severe psychological distress for the user. Furthermore, entering credit card information into the extortion portal immediately compromises that financial data, leading to secondary fraud.\n\n<h3>Remediation and Eradication</h3>\n<ul>\n<li><strong>Safe Mode Eradication:</strong> Because Recory actively terminates security tools, the infected endpoint must usually be booted into Windows Safe Mode. From Safe Mode, a reputable, enterprise-grade anti-malware solution can be run to detect and remove the Fake AV executables and repair the hijacked registry keys.</li>\n<li><strong>Do Not Pay the Ransom:</strong> Under no circumstances should the user enter their credit card information. The software is fake, and payment will simply result in stolen financial data.</li>\n<li><strong>System Restoration:</strong> In severe cases where the malware has heavily damaged the registry or hidden critical system files, restoring the machine from a known-good backup or utilizing Windows System Restore may be the most efficient path to recovery.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "FakeAV.Recory",
    "Ransom.Recory",
    "Scareware.Win32/Recory"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1491.001",
    "T1489",
    "T1547.001"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T17:02:47Z",
  "type": "Ransomware / Fake AV",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}