Press Ransomware Threatens Double Extortion

Press is a form of ransomware, a type of malicious program designed to encrypt data and demand payment for its decryption. In a similar fashion, the Press ransomware renames encrypted files by adding a ".press" extension. For instance, a file originally named "1.jpg" becomes "1.jpg.press," and the same pattern applies to other affected files.

Upon completing the encryption process, the Press ransomware displays a ransom message titled "RECOVERY NFO.txt." This message asserts that the ransomware employs double extortion tactics, claiming that not only were the victim's files encrypted, but sensitive data was also extracted. The victim is informed that paying a ransom is necessary for recovery. Refusal to comply with the attackers' demands is warned to lead to the sale or online leakage of the stolen content.

Before making any payments, the victim is advised to test the decryption process by sending a few encrypted files to the cyber criminals, adhering to specified guidelines. The note cautions that modifying or deleting the locked files may result in decryption complications.

Press Ransom Note Threatens Data Leak

The full text of the Press ransom note reads as follows:

Hello!

We're sorry, but your data are stolen and encrypted.
In case of nonpayment - all sensitive information will be sold or made publicly accessible.
Compared to other ransomware we charge a lot less, so don't be stingy!
If you pay - we will provide you with decryption software and remove your data from our servers. We work honesty!
Warning! Do not delete or modify any files, it can lead to recovery problems!

You can contact us using TOX messenger without registration and SMS hxxps://tox.chat/download.html
Tox ID: ABF256935FB3F8E5DE4E0127A98300EA41B9F3F651598B1BF37823EA46E8017CC740F9FFED83

Or download Tor Browser hxxps://www.torproject.org/download/ , create an account on the mail service onionmail.org and email us at Tyhelpss@onionmail.org

Send us your KeyID and 2 files with SIMPLE extensions(jpg,xls,doc, etc… not databases!) and low sizes(max 2 mb) for free decryption.
Use -

Good luck!

Key Identifier:

How Can You Safeguard Your Data Against Ransomware Attacks?

Safeguarding your data against ransomware attacks is crucial in protecting your valuable information. Here are some key measures you can take to enhance your data security:

Backup Regularly:
Regularly back up your important data to an external device or a secure cloud service.
Ensure that the backup is not continuously connected to the network, as ransomware may also encrypt connected backup files.

Update Software:
Keep your operating system, antivirus software, and all applications up to date. Regular updates often include security patches that can help prevent vulnerabilities.

Install Reliable Security Software:
Use reputable antivirus and anti-malware software to detect and prevent ransomware infections. Keep the software updated for the latest protection.

Use Email Filtering:
Implement email filtering solutions to identify and block phishing emails, which are common vectors for ransomware distribution.

Restrict User Permissions:
Limit user access rights to only the necessary files and directories. This can prevent ransomware from spreading laterally across a network.

January 23, 2024
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.