Craa Ransomware Joins Host of Djvu Variants


During our analysis of malware samples, our team identified a new member of the Djvu family, known as Craa ransomware. This malicious software works by encrypting files on an infected computer and appending the extension ".craa" to their filenames. Additionally, a ransom note in the form of a text file called "_readme.txt" is created.

For instance, if "1.jpg" and "2.png" were encrypted by Craa, their new names would be "1.jpg.craa" and "2.png.craa". Craa ransomware is believed to be distributed along with infostealers like Vidar.

According to the instructions in the ransom note, the decryption of files is impossible without a specific key and decryption software. The attackers provide email addresses ( or that victims can use to contact them for more information on data decryption.

Moreover, the ransom note also includes the prices of $980 and $490, indicating that the decryption tools can be acquired at a lower price if the attackers are contacted within 72 hours.

Craa Demands Ransom of Nearly $1000

The full ransom note created by the Craa ransomware reads as follows:


Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:

Reserve e-mail address to contact us:

Your personal ID:

How Can You Protect Your Data from Ransomware Like Craa?

There are several steps you can take to protect your data from ransomware like Craa:

  • Keep your operating system and all software up to date with the latest security patches.
  • Use a reliable anti-virus and anti-malware software, and keep it updated.
  • Be cautious when opening email attachments or downloading files from the internet. Only open attachments or download files from trusted sources.
  • Regularly back up your important data to an external hard drive or cloud storage service. This will allow you to recover your files in case of a ransomware attack.
  • Use strong passwords and enable two-factor authentication for your accounts. This will make it harder for attackers to access your data.

By following these steps, you can significantly reduce the risk of a ransomware attack and protect your important data from being held hostage by attackers like Craa.

March 14, 2023

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.