While analyzing malware samples, we discovered a new variant of Djvu ransomware called Coaq. This particular strain encrypts files and modifies their names by adding the ".coaq" extension. Additionally, Coaq creates a ransom note file called "_readme.txt".

Since Coaq is related to Djvu ransomware, it may be distributed along with other malware, such as RedLine or Vidar, which are known to steal data. As an example, if a file was originally named "1.jpg", after encryption, it would become "1.jpg.coaq", and so on.

The ransom note left by Coaq includes two email addresses ( and and urges victims to contact the attackers within 72 hours. The goal is to persuade the victims to pay a lower fee of $490 for decryption tools instead of the higher amount of $980, which would be charged after the initial 72-hour window.

The ransom note also emphasizes that decryption of the victim's files is impossible without purchasing the decryption software and a unique key from the attackers. Additionally, Coaq offers an option for victims to send a file for free decryption before making any payment.

The Coaq Ransom Note Uses Familiar Template

The complete ransom note used by the Coaq ransomware is the same one used in every other Djvu variant and reads as follows:


Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:

Reserve e-mail address to contact us:

Your personal ID:

How Can You Protect Your Home System from Ransomware Similar to Coaq?

There are several steps you can take to protect your home system from ransomware attacks similar to Coaq:

  • Keep your operating system and security software up to date: Make sure your system is running the latest operating system updates and security patches. Keep your antivirus software up to date, and run regular scans to detect and remove any malware.
  • Backup your data regularly: Create regular backups of your important files and store them on a separate device or in the cloud. This way, if your system is compromised by ransomware, you can easily restore your data without paying a ransom.
  • Be cautious when opening email attachments and downloading files: Do not open email attachments or download files from unknown or suspicious sources. Be wary of emails from unknown senders, especially those with suspicious attachments or links.
  • Use strong passwords and two-factor authentication: Use strong and unique passwords for all your accounts and enable two-factor authentication whenever possible. This can help prevent unauthorized access to your accounts and sensitive data.
  • Use a reputable anti-malware solution: Install a reputable anti-malware solution that can detect and block ransomware attacks.
  • Keep your software updated: Update all software installed on your system, including web browsers, plugins, and applications, to prevent known vulnerabilities that could be exploited by ransomware.
  • Use a firewall: Configure your firewall to block incoming connections to your system and only allow necessary outbound connections. This can help prevent unauthorized access to your system and data.

By following these steps, you can significantly reduce the risk of falling victim to ransomware attacks like Coaq and protect your system and data from harm.

March 7, 2023

