BTC (Voidcrypt) Ransomware

ransomware

Researchers have singled out a new ransomware variant. The new strain is called BTC ransomware and belongs to the wider family of Voidcrypt ransomware strains.

Unlike other recent clones of the Djvu ransomware family, BTC changes files more drastically upon encryption. Encrypted files receive a new extension, containing the victim ID string, the email used by the malware operator for contact and the BTC string at the end. In this way, a file previously called "house.jpg" will turn into "house.jpg.(VICTIM-ID)(RansomwareSupport at zohomail dot com).BTC" when encrypted.

The ransom note is dumped into a file named "unlock-info.txt", which is placed on the desktop of the infected system.

The full text of the ransom note dropped upon encryption is as follows:

All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail; RansomwareSupport at ZohoMail dot com

Write this ID in the title of your message : [alphanumeric string]

In case of no answer in 24 hours write us to theese e-mails: Zeini.p73 at gmail dot com

You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.

Free decryption as guarantee

Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins

The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.

hxxps://localbitcoins.com/buy_bitcoins

Also you can find other places to buy Bitcoins and beginners guide here:

hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!

Do not rename encrypted files.

Do not try to decrypt your data using third party software, it may cause permanent data loss.

Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

Victims should keep in mind that there is no way to know if a working encryption tool will ever be sent, even if the ransom is paid, and backup remains the best option for restoring files.

May 19, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.