The Money Message ransomware targets both the Windows and Linux operating systems and exfiltrates sensitive data before encryption.
The malware creates a custom mutex stops a range of services and processes and deletes all Volume Shadow Copy Service (VSS) snapshots.
The Elliptic Curve Diffie-Hellman (ECDH) key exchange and ChaCha stream cipher algorithm are leveraged for encryption while a ransom note is created in money_message.log.