Gatq Ransomware is a Djvu Clone Seeking Files To Encrypt


During our analysis of newly discovered malware samples, a new ransomware variant named Gatq emerged, which belongs to the Djvu malware family.

Gatq operates by encrypting files and appending the ".gatq" extension to their names. Additionally, it generates a text file titled "_readme.txt" that serves as a ransom note.

To illustrate the file renaming process employed by Gatq, it transforms "1.jpg" into "1.jpg.gatq," "2.png" into "2.png.gatq," and so on. It's important to note that Gatq may be distributed alongside other malware strains like Vidar and RedLine due to its association with the Djvu family.

The ransom note provided by Gatq states that victims must pay a fee to obtain the decryption software and a unique key to access their files. If the victims contact the threat actors within 72 hours, they have the option to purchase the decryption tools for $490. However, if the deadline is missed, the full amount of $980 is required. The ransom note includes two email addresses for support: and

Furthermore, the ransom note specifies that victims can send one file that does not contain any valuable data to the attackers prior to making the payment. This particular file will be decrypted free of charge.

Gatq Ransom Note Asks for Modesn Ransom Sum

The full text of the Gatq ransom note reads as follows:


Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:

Reserve e-mail address to contact us:

Your personal ID:

How Can You Protect Your System from Ransomware Like Gatq?

To protect your system from ransomware such as Gatq, it is crucial to implement a multi-layered approach that combines preventive measures and proactive security practices. Here are some steps you can take to safeguard your system:

  • Keep your software up to date: Regularly update your operating system, applications, and security software to ensure you have the latest patches and fixes. This helps address vulnerabilities that ransomware may exploit.
  • Install reputable security software: Deploy a robust antivirus/anti-malware solution that can detect and block known ransomware strains. Keep the security software updated with the latest threat definitions.
  • Exercise caution with email attachments and links: Be vigilant while opening email attachments or clicking on links, especially if they are from unknown or suspicious sources. Ransomware often spreads through phishing emails, so exercise caution and verify the legitimacy of the sender before interacting with any attachments or links.
  • Enable macro security in Office programs: Configure your Microsoft Office suite to block macros from running automatically. Ransomware can use malicious macros to infect systems, so it's important to disable this functionality unless explicitly trusted.
  • Backup your files regularly: Maintain regular backups of your important data on offline or cloud storage that is not directly accessible from your computer. This way, even if your system gets infected, you can restore your files from a backup without paying the ransom.
  • Enable file extensions: By displaying file extensions, you can easily identify suspicious file types. Ransomware often tries to hide its true nature by disguising itself as harmless files, but when you can see the file extensions, it becomes easier to spot malicious files.
May 22, 2023

