Gaqq Ransomware is Another Djvu Variant Targeting Files for Encryption

ransomware

During our examination of malware samples, our team came across a new ransomware variant called Gaqq, which belongs to the Djvu ransomware family. Gaqq primarily focuses on encrypting files, but it also modifies filenames by adding the ".gaqq" extension. Furthermore, it generates a ransom note named "_readme.txt."

For example, Gaqq takes a file named "1.jpg" and changes it to "1.jpg.gaqq." The same pattern applies to other files like "2.png," which becomes "2.png.gaqq." In some instances, cybercriminals employ additional malware like RedLine and Vidar to extract sensitive information before using the Djvu ransomware to encrypt the files.

The ransom note provided by Gaqq contains contact information for the attackers, specifically the email addresses support@freshmail.top and datarestorehelp@airmail.cc. The note emphasizes the urgency of contacting them within 72 hours to prevent the ransom fee from increasing to $980, double the initial amount of $490, for obtaining the decryption software and key.

Moreover, the note mentions a peculiar offer to victims. They can send one encrypted file to the cybercriminals, who will decrypt it for free. However, it is important to note that the file must not contain crucial or valuable data.

Gaqq Ransom Note Increases Ransom After 72 Hours

The complete text of the Gaqq ransom note reads as follows:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-ZyZya4Vb8D
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
support@freshmail.top

Reserve e-mail address to contact us:
datarestorehelp@airmail.cc

Your personal ID:

How Can Ransomware Like Gaqq Infect Your System?

Ransomware like Gaqq can infect your system through various means. Here are some common infection vectors:

  • Email Attachments: Hackers often use phishing emails to distribute ransomware. They send malicious emails disguised as legitimate messages, typically with infected attachments such as PDFs, Word documents, or executable files. When you open the attachment, the ransomware gets executed and starts encrypting your files.
  • Malicious Links: Cybercriminals may send phishing emails containing links to infected websites or compromised web pages. Clicking on these links can lead to the automatic download and execution of ransomware on your system.
  • Malvertising: Malicious advertisements, or malvertisements, can deliver ransomware. Hackers compromise legitimate ad networks, allowing them to inject malicious code into online ads. Clicking on these infected ads can redirect you to websites that distribute ransomware.
  • Exploit Kits: Ransomware can exploit vulnerabilities in outdated software or operating systems. By visiting compromised or malicious websites, your system may become a target for exploit kits that scan for security weaknesses and deliver ransomware payloads.
  • Social Engineering: Hackers often use social engineering techniques to trick users into downloading or executing ransomware. This can include fake software updates, deceptive pop-up messages, or misleading downloads that appear legitimate but are actually malicious.
  • Remote Desktop Protocol (RDP) Attacks: If your computer has RDP enabled and its credentials are weak or compromised, attackers can gain unauthorized access. Once inside your system, they can deploy ransomware and encrypt your files.

It is crucial to implement preventive measures to protect against ransomware infections. These include regularly updating software and operating systems, using strong and unique passwords, exercising caution when opening email attachments or clicking on links, employing reputable antivirus/antimalware software, and backing up your important files regularly to offline or cloud storage.

What is and How To Stop and Remove GAQQ Ransomware

July 12, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.