What is the APT14CHIR Ransomware?

APT14CHIR is a type of ransomware that our team discovered during the analysis of samples submitted to the online threat databases. The ransomware's primary goal is to encrypt files and rename them by replacing their original filenames with random characters and appending the ".APT14CHIR" extension. For instance, "1.jpg" may become "45bHrwLR0CmRGayY.APT14CHIR".

APT14CHIR's ransom note, found in a file named "PLEASE READ.txt," reveals that the attackers have fully encrypted the victim's critical files using the AES encryption algorithm. Any attempts to recover the files with third-party software could lead to permanent data loss, as well as modify or rename the encrypted files.

The attackers claim that they are the only ones who can decrypt the files and have uploaded all confidential data and a copy of the main servers to private storage. They threaten to make this information public if the victim decides not to pay the ransom.

In the note, the attackers assure the victim that they do not intend to cause any harm to their reputation or business, but only seek money. To get more information on how to decrypt the files, the victim must contact the attackers through email addresses martin_catch_ithelp@tutanota.com and martin_catch_ithelp@proton.me or the qTox messenger. It is worth noting that there is no third-party software available on the internet that can help decrypt the files.

APT14CHIR Ransom Note Uses Broken English

The complete text of the ransom note used by the APT14CHIR ransomware is written by non-native speakers and reads as follows:

HELLO, YOUR COMPANY NETWORK HAS BEEN PENETRATED
All your important files have been encrypted!

Your files NOT DAMAGE! Only fully modified. (RSA+AES)
They are encrypted with a strong unique aes encryption algorithm.

ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE
WILL PERMANENTLY CORRUPT IT.
DO NOT MODIFY ENCRYPTED FILES.
DO NOT RENAME ENCRYPTED FILES.

No software available on internet can help you. We are the only ones able to
solve your problem.

We uploaded all highly confidential/personal data and copy main servers.
These data are currently stored on a private storage.
This server will be immediately destroyed after your payment.
If you decide to not pay, we will release your data to public or re-seller, competitors, local government representative, judiciary, blackmail and attack intermediary
So you can expect your data to be publicly available in the near future..

We only seek money and our goal is not to damage your reputation or prevent
your business from destroy.

For more information and decryption keys, please contact us:
Martin_Catch_ITHELP@tutanota.com
Martin_Catch_ITHELP@proton.me

You will be provided with all the information about the necessary actions to fully decrypt your files.

You can also contact us using the qTox messenger, it will be much faster, support is available 24/7.

You can download from the link, or find the application yourself:

Contact qTox 24/7:
(alphanumeric string)

Your personal id:

APT14CHIR

How Can You Protect Your System from Ransomware Similar to APT14CHIR?

There are several steps you can take to protect your system from ransomware similar to APT14CHIR:

  • Keep your operating system and software up to date with the latest security patches and updates.
  • Install and regularly update antivirus and anti-malware software.
  • Be cautious when opening email attachments or clicking on links in emails from unknown or suspicious senders.
  • Back up your important data regularly to an external drive or cloud-based storage.
  • Use strong and unique passwords for all your accounts and enable two-factor authentication whenever possible.
  • Avoid downloading and installing software from untrusted sources.
  • Educate yourself and your family members about ransomware and how to recognize and avoid it.
  • Consider using a virtual private network (VPN) to encrypt your online activity and protect your personal information from cybercriminals.

By following these guidelines, you can reduce the risk of falling victim to ransomware attacks and protect your data from encryption by malicious actors.

February 17, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.