SchoolBoys Ransomware Uses Aggressive LockBit 3.0 Code
SchoolBoys ransomware is a new strain of file-encrypting malware that is built using the LockBit 3.0 ransomware code that was leaked online in recent weeks.
SchoolBoys will encrypt nearly every file found on the victim system. Once encrypted, files receive a new extension appended after their original one. The extension is a string of 9 random alphanumeric characters. This means that a file named "document.doc" may turn into something like "document.doc.pou19lkR3".
Encrypted files also receive their own icon to go along with the new extension assigned to them. Once encryption finishes, the ransomware drops its ransom demands inside a text file. The name of that file will be made up of the same string used for encrypted file extensions, with ".README.txt" appended after it.
The full ransom note goes as follows:
~~~~~SchoolBoys Ransomware Gang~~~~~
>>>> Your data are stolen and encrypted
The data will be published on TOR website if you do not pay the ransom
Links for Tor Browser:
hxxps://pnanlicgxkku2aonwsg2fwid3maycsso7joqnzp66wkfemzdk7ahsdid.onion
Your personal password for communication:-
>>>> What guarantees that we will not deceive you?
We are not a politically motivated group and we do not need anything other than your money.
If you pay, we will provide you the programs for decryption and we will delete your data.
Life is too short to be sad. Be not sad, money, it is only paper.
If we do not give you decrypters, or we do not delete your data after payment, then nobody will pay us in the future.
Therefore to us our reputation is very important. We attack the companies worldwide and there is no dissatisfied victim after payment.
>>>> You need contact us and decrypt one file for free on these TOR sites with your personal DECRYPTION ID
Download and install TOR Browser hxxps://www.torproject.org/
Write to a chat and wait for the answer, we will always answer you.
Links for Tor Browser:
hxxps://pnanlicgxkku2aonwsg2fwid3maycsso7joqnzp66wkfemzdk7ahsdid.onion
>>>> Your personal DECRYPTION ID: -
>>>> Warning! Do not DELETE or MODIFY any files, it can lead to recovery problems!
>>>> Warning! If you do not pay the ransom we will attack your company repeatedly again!