Popn Ransomware Follows Djvu Pattern

ransomware

During our examination of malicious file samples, we encountered Popn, a ransomware variant associated with the Djvu family. Popn deploys file encryption to block access to files and alters their names by appending the ".Popn" extension. Additionally, it generates a ransom note named "_readme.txt."

To demonstrate how Popn changes file names, it converts "1.jpg" to "1.jpg.Popn," "2.png" to "2.png.Popn," and so forth. It's important to mention that Popn may be distributed alongside information stealers like Vidar and RedLine.

The ransom note aims to reassure victims by providing them with an opportunity to recover their files. It claims that a wide range of files, such as pictures, databases, documents, and other vital data, have undergone encryption using a robust encryption method and a unique key.

As per the ransom note, the only way to regain access to the encrypted files is by acquiring a decryption tool and the corresponding unique key, which comes at a cost of $980.

Nevertheless, if victims establish contact with the attackers within the initial 72 hours, they become eligible for a 50% discount, reducing the price to $490. To initiate communication, the ransom note supplies two email addresses: restorealldata@firemail.cc and gorentos@bitmessage.ch.

Popn Ransom Note Copies Djvu Format

The full text of the Popn ransom note reads as follows:

ATTENTION!

Don't worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-WbgTMF1Jmw
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
restorealldata@firemail.cc

Reserve e-mail address to contact us:
gorentos@bitmessage.ch

Our Telegram account:
@datarestore

Your personal ID:

How Can You Safeguard Your Data Against Ransomware?

Safeguarding your data against ransomware requires a combination of preventive measures and proactive practices. Here are some essential steps you can take to protect your data from ransomware attacks:

  • Regular Backups: Regularly back up your important data and files to an external hard drive or a secure cloud storage service. This ensures that even if your primary data is encrypted by ransomware, you have a clean backup to restore from.
  • Keep Software Up to Date: Keep your operating system, applications, and security software up to date with the latest patches and updates. Software updates often include security fixes that can protect against known vulnerabilities exploited by ransomware.
  • Use Antivirus and Anti-Malware Software: Install reputable antivirus and anti-malware software on your devices and keep them updated. These programs can help detect and prevent ransomware infections.
  • Be Cautious with Email Attachments and Links: Exercise caution when opening email attachments or clicking on links, especially from unknown or suspicious sources. Phishing emails are a common method used to distribute ransomware.
  • Enable Macros with Caution: Be cautious when enabling macros in documents, especially in email attachments. Macros can be used to deliver ransomware.
  • Educate Employees and Users: Educate yourself and your employees about ransomware and phishing attacks. Raise awareness about the risks, warning signs, and best practices to avoid falling victim to such attacks.
  • Use Strong Passwords and Multi-Factor Authentication (MFA): Ensure that all accounts are protected with strong, unique passwords and enable multi-factor authentication whenever possible. This adds an extra layer of security to your accounts.
August 1, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.