Nerz Ransomware is Based on Djvu Code to Target Random Files

ransomware

During our analysis of malicious file samples, our team recently came across a variant of the Djvu ransomware family called Nerz. Similarly to its counterparts, Nerz encrypts data but adds the ".nerz" extension to the affected files. Once the encryption process is finished, a ransom note titled "_readme.txt" is left behind.

Nerz employs a specific file renaming pattern, where it alters names like "1.jpg" to "1.jpg.nerz," "2.png" to "2.png.nerz," and so on. Considering its connection to the Djvu family, it is possible that Nerz is distributed in conjunction with other malicious software such as RedLine, Vidar, and other information stealers.

After conducting a thorough examination of the ransom note, we deduced its primary objective: to provide victims with instructions on how to contact the attackers and make a ransom payment. Within the "_readme.txt" file, two email addresses are disclosed—support@freshmail.top and datarestorehelp@airmail.cc. Additionally, the note outlines two ransom amounts: $980 and $490.

The note explicitly emphasizes that victims can obtain the decryption tools, which include the necessary software and key, at a discounted rate if they initiate contact with the attackers within a 72-hour timeframe.

Nerz Ransom Note Asks for $980 if Ransom is Late

The full text of the Nerz ransom note reads as follows:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted
with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-vc50LyB2yb
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
support@freshmail.top

Reserve e-mail address to contact us:
datarestorehelp@airmail.cc

Your personal ID:

How Can You Protect Your Data from Ransomware Like Nerz?

Safeguarding your data from ransomware such as Nerz requires proactive measures and best practices. Here are some steps you can take to protect your data:

  • Backup Your Data: Regularly backup your important files to an external storage device or cloud backup service. Ensure that backups are offline or disconnected from the network to prevent them from being compromised in the event of a ransomware attack.
  • Keep Software Updated: Keep your operating system, antivirus software, and all applications up to date with the latest security patches. Regularly apply updates to address vulnerabilities that attackers may exploit.
  • Exercise Caution with Email Attachments and Links: Be cautious when opening email attachments or clicking on links, especially if they are from unknown senders or seem suspicious. Verify the legitimacy of the sender and scan attachments for malware before opening them.
  • Use Reliable Security Software: Install reputable antivirus or antimalware software and keep it updated. Enable real-time scanning and automatic updates to detect and block ransomware threats effectively.
  • Enable Firewall and Intrusion Detection Systems: Activate firewalls on your devices and network to monitor incoming and outgoing traffic. Implement intrusion detection and prevention systems to identify and block suspicious activity.
  • Practice Safe Web Browsing: Be cautious when visiting websites, especially those of questionable reputation. Avoid clicking on pop-up ads or downloading files from untrusted sources.
  • Disable Macros in Office Documents: Disable macros in Microsoft Office documents by default. This reduces the risk of malicious macros launching ransomware.
  • Implement Least Privilege Access: Use the principle of least privilege, granting users only the minimum level of access necessary to perform their tasks. Restrict administrative privileges to prevent unauthorized software installations.
June 6, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.