Nzoq Ransomware Encrypts Target Systems

ransomware

Our team of researchers recently discovered a fresh addition to the Djvu ransomware family named Nzoq. Nzoq is a malicious program designed to lock files through encryption, rendering them inaccessible. Our encounter with Nzoq took place during the evaluation of new file samples.

Nzoq might be disseminated in conjunction with other malicious software like RedLine or Vidar. Once it infiltrates a computer system, it alters the names of encrypted files by appending the ".nzoq" extension. For instance, filenames such as "1.jpg" are transformed into "1.jpg.nzoq," and "2.png" becomes "2.png.nzoq." The malware also leaves behind a ransom note named "_readme.txt."

This ransom note includes details for making payment and establishing contact, while also emphasizing the urgency for victims to communicate with the threat actors within 72 hours. Failure to do so could result in an increase of the ransom amount from $490 to $980. This payment covers the cost of acquiring decryption tools necessary for recovering the encrypted files.

Furthermore, victims are offered an opportunity to decrypt a single file at no cost. They can achieve this by sending the chosen file to the provided email addresses: support@freshmail.top and datarestorehelp@airmail.cc. These same email addresses are to be used for reaching out to the cybercriminals regarding the decryption of data.

Nzoq Ransom Note Demands $490 in Payment

The full text of the Nzoq ransom note reads as follows:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-E4b0Td2MBH
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
support@freshmail.top

Reserve e-mail address to contact us:
datarestorehelp@airmail.cc

Your personal ID:

How Can Ransomware Like Nzoq Infect Your Computer?

Ransomware like Nzoq can infect your computer through various methods, often relying on tactics that exploit vulnerabilities, trick users, or manipulate software. Here are some common ways ransomware like Nzoq can find its way onto your computer:

  • Malicious Email Attachments: Cybercriminals often send out phishing emails with attachments that appear harmless (such as PDFs or Word documents), but are actually loaded with ransomware. Once the attachment is opened, the ransomware gets activated.
  • Infected Links: Malicious links in emails, instant messages, or on websites can lead you to websites hosting ransomware. Clicking on such links can trigger the download and installation of the ransomware onto your system.
  • Drive-By Downloads: Malicious code can be injected into legitimate websites. If you visit a compromised website, the malicious code can silently download ransomware onto your computer without your knowledge.
  • Malvertising: Cybercriminals use malicious advertisements that can appear on legitimate websites. Clicking on these ads can lead to ransomware infection.
  • Exploit Kits: These are toolkits that target vulnerabilities in software applications, often ones that users have failed to update. When a user visits a compromised website, the exploit kit scans for vulnerabilities and delivers ransomware through those weaknesses.
  • Software Vulnerabilities: Ransomware can exploit known vulnerabilities in your operating system or other software applications that have not been patched with the latest security updates.
  • Remote Desktop Protocol (RDP) Attacks: If your RDP is not properly secured, attackers can exploit weak passwords or vulnerabilities in the RDP protocol to gain access to your computer and install ransomware.
  • Malicious Downloads: Downloading pirated software, cracks, or keygens from untrustworthy sources can expose you to ransomware. Cybercriminals often hide ransomware in seemingly innocent software downloads.
August 31, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.