RED BANNER Ransomware Asks for 0.01 BTC as Ransom Despite Being a Fake

During our review of malware samples, our team came across a type of fake ransomware known as "scareware" called RED BANNER. This malicious software is designed to trick unsuspecting users into believing that their files have been encrypted, and they must pay a ransom to regain access.

When RED BANNER infects a computer, it displays a full-screen message (referred to as a ransom note) that includes instructions for making the payment. The ransom note informs the user that all their data has been encrypted and uploaded to the network, and that their computer is in a critical state. The note demands a payment of 0.010 BTC (approximately $280) to a specific address to decrypt the data and restore access. The language used in the note is hostile and crude.

RED BANNER Ransom Note Asks for Around $300 in BTC

The full text of the RED BANNER ransom note goes as follows:

RED BANNER

Opps, all your data is encrypted

What's wrong with my computer?

All your files are uploaded to the network, encrpyted and fked in the a

What should i do?

If you are a beggar, then your computer is officially f**ked
If you have 0.010 BTC ($280) then transfer it here bc1q23q7wk5jtv9vhp8433gct673y4f5ny30njwzad and thenwe will decrypt your data and restore access to your computer

Transfer here 0.010 BTC and then we will unlock access to your computer

bc1q23q7wk5jtv9vhp8433gct673y4f5ny30njwzad

By Cursed Team

What Are Fake Ransomware Variants That Don't Encrypt Files?

Fake ransomware variants, also known as scareware, are a type of malicious software that does not actually encrypt files. Instead, these variants display fake ransom notes that try to scare the victim into paying a ransom to regain access to their files or system.

Some common fake ransomware variants include:

  • RED BANNER: As previously mentioned, this variant displays a full-screen message that claims to have encrypted the victim's data and demands a ransom payment to restore access.
  • FileCoder: This variant displays a message that claims to have encrypted the victim's files, but in reality, it simply renames the files with a fake extension. The fake ransom note demands a payment to restore access to the files.
  • Winlocker: This variant locks the victim's computer and displays a fake message that claims to be from law enforcement. The message accuses the victim of illegal activities and demands a payment to unlock the computer.
  • Police Locker: Similar to Winlocker, this variant locks the victim's computer and displays a fake message that claims to be from law enforcement. The message accuses the victim of illegal activities and demands a payment to unlock the computer.

These fake ransomware variants can be just as dangerous as real ransomware because they can cause panic and lead victims to pay the ransom even though their files have not actually been encrypted. It is important to have proper anti-malware protection and to verify the legitimacy of any ransom notes before taking any action.

April 7, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.