Mmob Ransomware

ransomware

Mmob is a newly discovered strain of ransomware. The new ransomware belongs to the wider family known as the Djvu ransomware family, which includes other strains tracked under different names and sharing some similarities.

Once it executes on a victim system, the Mmob ransomware will encrypt files on it, making them inaccessible. Encrypted files cannot be opened using normal means as the information inside has been scrambled. Encrypted files also simply receive the ".mmbo" extension appended behind their regular one. In this way, a file originally called "ledger.pdf" will turn into "ledger.pdf.mmob" once the Mmob ransomware has made a pass over it and encrypted its contents.

The ransomware will target most popular document and media file types, including mp3, pictures stored in jpg, as well as video files. Once encryption is complete, the ransomware drops its ransom demands in a file called "_readme.txt".

The full text of the ransom note reads as follows:

ATTENTION!

Don't worry, you can return all your files!

All your files like photos, databases, documents, and other important are encrypted with strongest encryption and unique key.

The only method of recovering files is to purchase decrypt tool and unique key for you.

This software will decrypt all your encrypted files.

What guarantees you have?

You can send one of your encrypted file from your PC and we decrypt it for free.

But we can decrypt only 1 file for free. File must not contain valuable information.

You can get and look video overview decrypt tool:

hxxps://we.tl/t-WbgTMF1Jmw

Price of private key and decrypt software is $980.

Discount 50% available if you contact us first 72 hours, that's price for you is $490.

Please note that you'll never restore your data without payment.

Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:

 restorealldata at firemail dot cc

Reserve e-mail address to contact us:

 gorentos at bitmessage dot ch

Our Telegram account:

at datarestore

Your personal ID:

There is no free decryption tool available for this ransomware. The ransom note offers free decryption of just one file, to prove that the hackers have the tools required to restore your data. Bear in mind that paying the hackers, no matter if you do it within 72 hours like they expect you to, or later on, will guarantee that you will have your files restored.

May 4, 2022