DECAF Ransomware Creators Jump on the Golang Bandwagon

The Go programming language is starting to become and more desirable by cybercriminals worldwide. It provides them with the ability to build implants compatible with multiple desktop operating systems, and to also use experimental obfuscation techniques that make it easier to evade security tools. The first malware attacks with Golang-based malware date back to 2019, but the number of Golang projects has been rapidly increasing since then. The latest implant to join the list of Golang-based file-lockers is the DECAF Ransomware.

Two other notable ransomware families that make use of the Go programming language are the BabukLocker and Hive Ransomware. The DECAF Ransomware is not related to either of those, and it appears to be the product of an unidentified malware gang. Since the first version of this implant was discovered, its creators have released several updates, enhancing the payload's functionality and security.

Golang-based DECAF Ransomware Operates Just Like Other File-locking Malware

Just like other file-encryption Trojans, the DECAF Ransomware also focuses on locking users out of their files, and then extorts them for money. Of course, the project is not one of the simple ones – it is clear that its authors have experience in malware development with the Go programming language.

All files that the DECAF Ransomware are marked with the '.decaf' extension. It drops the ransom note 'README.txt.' During its attack, it will ignore a specific set of files, folders, and extensions in order to prevent the ransomware from bricking the operating system or specific software. It also helps to avoid double-encrypting files.

So far, free decryption options are not available. Victims of the DECAF Ransomware should not accept to send any money to the criminals, even if they provide proof of their ability to decipher files. Remember that the developers of file-lockers are not trustworthy, and they may attempt to scam you out of your money. If you are a victim of the DECAF Ransomware, you should use an antivirus scanner to eliminate the threat. Then, experiment with alternative data recovery tools and options, or try to recover files from a backup.

November 1, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.