Helphack Ransomware Spotted in the Wild
A new ransomware clone based on Chaos ransomware code has been spotted in the wild. The new version is called the Helphack ransomware.
Helphack encrypts files on the victim's system, making their contents unreadable. Once encrypted, files receive a new extension that consists of four randomly generated alphanumeric characters. This means that a file previously called "letter.doc" will turn into something similar to "letter.doc.yv9m".
Affected file types include the majority of media, document, archive and database extensions.
The ransomware drops its ransom demands inside a plain text file named "read_it.txt", asking for $3000 worth of BTC.
The ransom note in full goes as follows:
your data has been encrypted but don't worry you can recover it by making a small donation of 3000 dollars in Bitcoin (BTC) to this
Address: [alphanumeric string]
send capture to
contact: helphack94749 at protonmail dot com
There is no known decryption tool for the Helphack ransomware so your best bet is to restore files from offline backup devices.








