Pig865qq Ransomware Encrypts Systems

During our routine analysis of malware samples submitted to the VirusTotal website, we have detected the Pig865qq ransomware, which belongs to the GlobeImposter family. Pig865qq encrypts files, adds the ".Pig865qq" extension to them, and presents a ransom note named "HOW TO BACK YOUR FILES.exe."

As an illustration of Pig865qq's file modification, it transforms filenames such as "1.jpg" into "1.jpg.Pig865qq" and "2.png" into "2.png.Pig865qq."

The ransom note notifies the victim about the encryption of their files and provides guidelines for decryption. It instructs the individual to reach out to the specified email address, china.helper@aol.com, and submit one encrypted test image, text file, or document along with their personal ID.

The note emphasizes the exclusivity of the attackers' decryption services and advises against seeking assistance from other services to avoid potential fraud. Notably, it warns against using antivirus programs that might delete the document, hindering future communication.

Furthermore, the note discourages attempts at self-decrypting files, claiming potential data loss. It asserts that decoders from other users are incompatible due to unique encryption keys for each user.

Pig865qq Ransom Note in Full

The complete text of the Pig865qq ransom note reads as follows:

Your files are encrypted!

To decrypt, follow the instructions below.
To recover data you need decrypt tool.
To get the decrypt tool you should:

Send 1 crypted test image or text file or document to China.Helper@aol.com
In the letter include your personal ID (look at the beginning of this document). Send me this ID in your first email to me.
We will give you free test for decrypt few files (NOT VALUE) and assign the price for decryption all files.
After we send you instruction how to pay for decrypt tool and after payment you will receive a decrypt tool and instructions how to use it We can decrypt few files in quality the evidence that we have the decoder.

MOST IMPORTANT!!!

Do not contact other services that promise to decrypt your files, this is fraud on their part! They will buy a decoder from us, and you will pay more for his services. No one, except China.Helper@aol.com, will decrypt your files.

Only China.Helper@aol.com can decrypt your files
Do not trust anyone besides China.Helper@aol.com
Antivirus programs can delete this document and you can not contact us later.
Attempts to self-decrypting files will result in the loss of your data
Decoders other users are not compatible with your data, because each user's unique encryption key

How Can You Protect Your Files from Ransomware?

Protecting your files from ransomware requires a combination of proactive measures and good cybersecurity practices. Here are some effective ways to safeguard your files from ransomware attacks:

Regular Backups:
Regularly back up your important files and data. Store backups on an external device or in a cloud service that is not directly connected to your computer.
Automate the backup process whenever possible to ensure consistency.

Update Software:
Keep your operating system, antivirus software, and all other applications up to date. Regular updates often include security patches that can protect against known vulnerabilities.

Use Reliable Security Software:
Install reputable antivirus and anti-malware software. Ensure that it is set to update automatically and conduct regular scans.

Exercise Caution with Email:
Be wary of email attachments and links, especially if they are from unknown or unexpected sources. Avoid opening attachments or clicking on links unless you are certain of their legitimacy.

Use a Firewall:
Enable a firewall on your computer to monitor and control incoming and outgoing network traffic. This adds an additional layer of protection against unauthorized access.

November 15, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.