Feg Ransomware Copies Xorist & Targets Russian PC Users
Feg is the name of a new ransomware strain that belongs to the Xorist family of ransomware clones.
Feg behaves the same as most ransomware clones. It will encrypt files on the targeted system's drives and change their names. The extension ".feg" is added after the original one on every encrypted file.
The ransomware will encrypt media files, documents, archives and executables.
When encryption finishes, the Feg ransomware drops its ransom demands inside a file called "КАК РАСШИФРОВАТЬ ФАЙЛЫ.txt". The same text is displayed in a pop-up window as well. The ransom note is written in Russian and threatens to destroy the decryption key if the hackers are not contacted within a day. The full note goes as follows:
Внимание! Все Ваши файлы зашифрованы!
Для того что бы расшифровать свои файлы напишите нам на почту:
marina99787 at mail dot ru
Ждем ответа сутки ,если не получим ответа сегодня, после удаляем ключи расшифровки.








