Baal Ransomware is a New Chaos Clone Designed To Encrypt Files For Ransom

During the examination of new threats submitted to online threat analysis databases, our team came across the Baal malware, which is based on the Chaos ransomware. We conducted a sample execution of the Baal ransomware on our testing system, which resulted in file encryption and changes in their names. The original names were modified by adding a four-character extension that was generated randomly, for instance, a file initially named "1.jpg" appeared as "1.jpg.vkwp", and so on.

After the encryption process, a ransom note with the name "read_it.txt" was created, and the desktop wallpaper was changed. The ransom message informs the victims that their data has been encrypted and the only way to recover it is by paying a ransom to the attackers. The note also provides the option of testing decryption by sending the cybercriminals three encrypted files.

The attackers demand a ransom of 121 BTC, which is equivalent to approximately 2.6 million USD at the current exchange rate. These large sums are typically demanded from organizations, institutions, and companies, rather than home users. After making the payment, the note instructs the victims to send a screenshot of the transaction to the attackers and they are given a six-day deadline to fulfill the ransom demand.

Baal Uses Lengthy Ransom Note

The ransom note produced by the Baal ransomware reads as follows:

YOUR PERSONAL INFORMATION IS NOW ENCRYPTED WITH MILITARY GRADE ENCRYPTION by BAAL RANSOMWARE

All files on all affected machines and network have been encrypted with Baal Ransomware Encryption.
What guarantees do we give to you?
You can send 2 of any encrypted files to us to decrypt then send them back.

Who is responsible for the Ransom Fee?
The SARB & SA Mint Organization not its employees or assosiates will need to pay the fee to obtain the unique decryption code & tool that contains the private key linked to this specific ecryption.

NOTE: All data is ecrypted (locked) not overitten hence can be decrypted with assossiated key only.

You have only 6 (six) days to meet the Ransom fee in Bitcoin.

Instructions:

  1. Send 121 BTC (Bitcoins) to the following receiving address:

alphanumeric string

Note: All Bitcoin transactions need six confirmations in the blockchain from miners before being processed. In general sending Bitcoin can take anywhere from seconds to over 60 minutes. Typically, however, it will take 10 to 20 minutes In most cases, Bitcoin transactions need 1 to 1.5 hours to complete.

  1. Send blockchain transaction id screenshot not link via to the email address:

blackbastabaalransomware@protonmail.com

  1. Once the transaction is be confirmed. We will email back the one-click decryption tool to fully decrypt and recover all your files and remove the randsomware on all your machines and network permantly. (No I.T. background required).
  2. The decryption usually takes about a few minutes to an hour depending on the scale and size of the files and additional drives the Ransomware has spread onto the network.

What guarantees do we give to you?
You can send 3 of your encrypted files and we decrypt then send them back.

You have 6 days until the decryption keys are terminated and all data on affected machines and networks will never be recovered. We make use of Military Grade AES Encryptions. Without the linked decryption key you can just forgot about ever recovering encrypted data.


'Blessed are the strong for they shall inherit the Earth' - Codex Saerus

Why Is it Not a Good Idea to Pay Ransom to Hackers?

It is generally not a good idea to pay a ransom to hackers for several reasons. First, paying a ransom does not guarantee that the attackers will actually provide the decryption key or release the encrypted files. Second, paying the ransom encourages further attacks and reinforces the behavior of cybercriminals. Third, the funds obtained from ransom payments can be used to finance other criminal activities. Finally, there is no way to ensure that the attackers will not come back for more money in the future, even after the ransom has been paid. As a result, experts generally recommend not paying the ransom and instead seeking assistance from cybersecurity professionals to recover the encrypted files, if possible.

February 17, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.