Warning! Zxc Ransomware Will Lock Your Files

During an investigation of new malware samples, our researchers came across the Zxc ransomware, which is a type of malicious program that belongs to the VoidCrypt ransomware family.

After running a Zxc sample on a test machine, it encrypted files and modified their filenames by appending a unique ID assigned to the victim, the email address of the cyber criminals, and a ".zxc" extension to the original file name. For instance, a file named "1.jpg" would appear as "1.jpg.(MJ-KO1579824036)(hionly@tutanota.com).zxc".

Once the encryption process was complete, the ransomware created ransom notes in the form of a pop-up window ("Decryption-Guide.HTA") and a text file ("Decryption-Guide.txt"). These ransom notes informed victims that their files were encrypted and provided instructions on how to contact the attackers to decrypt their affected data. However, paying the cyber criminals was required for decryption. The notes warned that modifying the encrypted files by renaming them, using third-party decryption tools, or reinstalling the operating system would result in permanent data loss.

Zxc Uses Standard VoidCrypt Ransom Note

The full text of the Zxc ransom note reads as follows:

Your Files Are Has Been Locked

Your Files Has Been Encrypted with cryptography Algorithm

If You Need Your Files And They are Important to You, Dont be shy Send Me an Email

Send Test File + The Key File on Your System (File Exist in C:/ProgramData example : RSAKEY-SE-24r6t523 pr RSAKEY.KEY) to Make Sure Your Files Can be Restored

Make an Agreement on Price with me and Pay

Get Decryption Tool + RSA Key AND Instruction For Decryption Process


1- Do Not Rename or Modify The Files (You May loose That file)

2- Do Not Try To Use 3rd Party Apps or Recovery Tools ( if You want to do that make an copy from Files and try on them and Waste Your time )

3-Do not Reinstall Operation System(Windows) You may loose the key File and Loose Your Files

4-Do Not Always Trust to Middle mans and negotiators (some of them are good but some of them agree on 4000usd for example and Asked 10000usd From Client) this Was happened

Your Case ID :-

OUR Email :hionly@tutanota.com

How Can You Protect Your System from Ransomware Like Zxc?

There are several measures you can take to protect your system from ransomware like Zxc:

  • Keep your system and software up-to-date with the latest security patches and updates.
  • Use antivirus and anti-malware software, and keep them updated.
  • Be cautious when opening email attachments or clicking on links, especially from unknown or suspicious sources.
  • Backup your data regularly and store it on an external hard drive or cloud storage.
  • Use strong and unique passwords, and enable two-factor authentication for added security.
  • Be wary of unexpected pop-ups or requests for access to your system, and only download software from trusted sources.

By following these steps, you can reduce your risk of falling victim to ransomware attacks like Zxc, and protect your system and data from harm.

March 9, 2023

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.