What is BlackBit Ransomware?

BlackBit is the name of a newly discovered strain of ransomware. The new variant belongs to the Loki Locker ransomware family.

The ransomware encrypts most files found on the targeted system. Encrypted file types include document, archive, media and database files.

Encrypted files have their names changed almost completely. A file named "document.doc" will transform into "[spystar@onionmail.org][victim ID]document.doc.BlackBit". The name includes the contact email used by the ransomware operator, the victim's ID code and the ".BlackBit" string.

The ransom note consists of two parts, deposited inside a plain text file named "Restore-My-Files.txt" and a pop-up window. The full ransom note goes as follows:


All your files have been encrypted by BLACKBIT!


All your files have been encrypted due to a security problem with your PC.

If you want to restore them, please send an email spystar at onionmail dot org

You have to pay for decryption in Bitcoin. The price depends on how fast you contact us.

After payment we will send you the decryption tool.

You have to 48 hours(2 Days) To contact or paying us After that, you have to Pay Double.

In case of no answer in 24 hours (1 Day) write to this email spystar1 at onionmail dot com

Your unique ID is : -

You only have LIMITED time to get back your files!

•If timer runs out and you dont pay us , all of files will be DELETED and you hard disk will be seriously DAMAGED.

•You will lose some of your data on day 2 in the timer.

•You can buy more time for pay. Just email us.

•THIS IS NOT A JOKE! you can wait for the timer to run out ,and watch deletion of your files 🙂

What is our decryption guarantee?

•Before paying you can send us up to 3 test files for free decryption. The total size of files must be less than 2Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)


•DO NOT pay any money before decrypting the test files.

•DO NOT trust any intermediary. they wont help you and you may be victim of scam. just email us , we help you in any steps.

•DO NOT reply to other emails. ONLY this two emails can help you.

•Do not rename encrypted files.

•Do not try to decrypt your data using third party software, it may cause permanent data loss.

•Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

How To Safely Detect, Stop, and Remove BlackBit Ransomware

September 21, 2022