Wspn Ransomware Will Scramble Your Data

ransomware

During our analysis of malware samples, our expert team stumbled upon a variant of Djvu ransomware called Wspn. Wspn's primary objective is to encrypt files, and it accomplishes this by appending the ".wspn" extension to modified filenames. Additionally, it leaves behind a ransom note named "_readme.txt."

As an illustration of its behavior, Wspn will alter filenames like "1.jpg" to "1.jpg.wspn" and "2.png" to "2.png.wspn." In some cases, cybercriminals utilize data-stealing malware like RedLine and Vidar to extract sensitive information before deploying Djvu ransomware for file encryption.

Inside the ransom note, the attackers provide contact details, including support@freshmail.top and datarestorehelp@airmail.cc email addresses. The note stresses the urgency of communication within 72 hours to avoid a higher ransom fee. Initially, the decryption software and key are offered at $490, but beyond the specified time frame, the ransom amount doubles to $980.

Moreover, the ransom note presents a provision allowing victims to send one encrypted file to the cybercriminals for decryption at no cost. However, the chosen file must not contain any crucial information.

Wspn Ransom Note Asks for $980 in Ransom Payment

The full text of the Wspn ransom note reads as follows:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-ujg4QBiBRu
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
support@freshmail.top

Reserve e-mail address to contact us:
datarestorehelp@airmail.cc

Your personal ID:

How Can Ransomware Like Wspn Get in Your System?

Ransomware like Wspn can find its way into your system through various methods. Some of the common ways ransomware infects systems include:

  • Phishing Emails: Phishing emails are a prevalent method for distributing ransomware. Cybercriminals send deceptive emails that appear legitimate, often with malicious attachments or links. Clicking on these links or opening infected attachments can trigger the ransomware installation.
  • Malicious Websites and Downloads: Visiting compromised or malicious websites and downloading software or files from untrustworthy sources can lead to ransomware infections. Some websites may contain drive-by download attacks that exploit vulnerabilities in your system to install ransomware silently.
  • Exploiting Software Vulnerabilities: Ransomware developers may exploit known vulnerabilities in software, operating systems, or applications to gain unauthorized access to your system and install the malware.
  • Malvertising: Cybercriminals can use malicious advertisements (malvertisements) on legitimate websites to deliver ransomware. Clicking on these ads can lead to unintentional ransomware downloads.
  • Social Engineering: Attackers may use social engineering techniques to trick users into executing ransomware on their systems. For example, they might pretend to be technical support personnel and convince users to install malicious software.
  • Remote Desktop Protocol (RDP) Attacks: If RDP is enabled without proper security measures, attackers can use brute-force attacks to gain access to systems and deploy ransomware.
  • Infected External Devices: Ransomware can spread through infected external devices such as USB drives or external hard drives if they are connected to an already compromised system.

How To Safely Stop & Remove WSPN Ransomware - Save Your Files From Encryption

July 28, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.