Newlocker Ransomware Joins Family of MedusaLocker Clones

During our inspection of malware samples, we discovered Newlocker, a ransomware program that is part of the MedusaLocker family. The ransomware encrypts files and adds the ".newlocker" extension to their names. It also creates a ransom note in the form of an HTML file named "HOW_TO_RECOVER_DATA.html".

For instance, a file named "1.jpg" is renamed to "1.jpg.newlocker", while "2.png" becomes "2.png.newlocker", and so on. The ransom note warns the victim that their network has been compromised and that important files have been encrypted using RSA and AES encryption algorithms. The attackers claim that third-party software cannot decrypt the files and that any attempts to do so will result in permanent loss of data.

The ransom note cautions the victim against changing or renaming the encrypted files and threatens to release highly confidential and personal data publicly or sell it if the ransom is not paid. The attackers offer to decrypt a few non-essential files for free as proof of their capability to recover the data.

The ransom note provides two email addresses for the victim to contact and make the ransom payment to receive the decryption key and software. It warns that the decryption key is only stored temporarily and that the victim should make contact as soon as possible. Additionally, if the victim does not contact the attackers within 72 hours, the ransom price will increase.

Newlocker Ransom Offers Decryption of a Few Files

The full text of the Newlocker ransom note reads as follows:

YOUR PERSONAL ID:

YOUR COMPANY NETWORK HAS BEEN PENETRATED
ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!

YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES)

ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE
WILL PERMENANTLY DESTROY YOUR FILE.
DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.

NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE
SOLUTION TO YOUR PROBLEM.

WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA
ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE
IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY
AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO
NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.

YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL
DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES
BACK.

CONTACT US FOR PRICE (BITCOIN) AND GET DECRYPTION SOFTWARE.

microhdd@tuta.io
microhdd@firemail.cc
MAKE CONTACT AS SOON AS POSSIBLE. YOUR DECRYPTION KEY IS ONLY STORED
TEMPORARLY. IF YOU DON'T CONTACT US WITHIN 72 HOURS, PRICE WILL BE HIGHER.

How Can You Protect Your Data from Ransomware Like Newlocker?

There are several steps you can take to protect your data from ransomware like Newlocker:

  • Backup your data regularly: Ensure you backup your important data regularly, and store the backups in a secure location, preferably offline.
  • Keep your software up to date: Make sure that you always update your operating system, antivirus, and other software regularly to protect against vulnerabilities that ransomware can exploit.
  • Use strong passwords and two-factor authentication: Use strong passwords and enable two-factor authentication wherever possible, as this can help prevent unauthorized access to your accounts.
  • Be careful when opening email attachments: Ransomware often spreads through email attachments, so avoid opening attachments from unknown senders, and be cautious even when opening attachments from known senders.
  • Use reputable security software: Install reputable antivirus and anti-malware software on your system and ensure they are updated regularly.
  • Be cautious when visiting websites: Avoid visiting potentially risky websites, and never download anything from untrusted sources.

By taking these precautions, you can significantly reduce the risk of ransomware infecting your system and keep your data safe.

May 10, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.