What is Joker Ransomware?


Joker ransomware is a newly discovered strain of file-encrypting malware. The new variant belongs to the VoidCrypt family.

The Joker ransomware encrypts the victim system, scrambling almost every file on it. Encrypted files receive a multi-string extension that consists of the victim ID code, the email used by the ransomware author and the ".Joker" string. This means that a file called "document.doc" will transform into "document.doc.(victim ID)(suppransomeware@tutanota.com).Joker".

Encrypted files will include all commonly used media, document, archive and database extensions.

The ransomware drops its ransom demands inside two files, named "Decryption-Guide.HTA" and "Decryption-Guide.txt". The HTA file is displayed in a pop-up window upon encryption completion. The text in it is as follows:

Your Files Are Has Been Locked

Your Files Has Been Encrypted with cryptography Algorithm

If You Need Your Files And They are Important to You, Dont be shy Send Me an Email

Send Test File + The Key File on Your System (File Exist in C:/ProgramData example : RSAKEY-SE-24r6t523 pr RSAKEY.KEY) to Make Sure Your Files Can be Restored

Make an Agreement on Price with me and Pay

Get Decryption Tool + RSA Key AND Instruction For Decryption Process


1- Do Not Rename or Modify The Files (You May loose That file)

2- Do Not Try To Use 3rd Party Apps or Recovery Tools ( if You want to do that make an copy from Files and try on them and Waste Your time )

3-Do not Reinstall Operation System(Windows) You may loose the key File and Loose Your Files

4-Do Not Always Trust to Middle mans and negotiators (some of them are good but some of them agree on 4000usd for example and Asked 10000usd From Client) this Was happened

Your Case ID :

OUR Email :suppransomeware at tutanota dot com

in Case of no answer: suppransomeware at mailfence dot com

September 20, 2022