Unique Ransomware Joins Phobos Clone Family

A new strain of ransomware belonging to the Phobos family was spotted by researchers this week. The new variant is called the Unique ransomware.

Unique encrypts files on the system and leaves them scrambled. Encrypted file extensions will include almost every media, document, archive and database file type.

Once encrypted, the files receive a new multi-part extension. It consists of the victim ID code, the email used by Unique's operator and the ".unique" extension. This will turn a file called "music.mp3" into "music.mp3.id[alphanumeric string].[uniqueproject@xsmail.com].unique" when it gets encrypted.

The ransomware drops its ransom note inside two separate files, named "info.hta" and "info.txt", just like every other recent Phobos clone. The more complete ransom note is contained in the HTA file that is displayed inside a pop-up window and goes as follows:

All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail uniqueproject at xsmail dot com

Write this ID in the title of your message -

In case of no answer in 24 hours write us to this e-mail:uniqueproject at fastmail dot com

You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the tool that will decrypt all your files.

Free decryption as guarantee

Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 4Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins

The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.

hxxps://localbitcoins.com/buy_bitcoins

Also you can find other places to buy Bitcoins and beginners guide here:

hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!

Do not rename encrypted files.

Do not try to decrypt your data using third party software, it may cause permanent data loss.

Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

September 28, 2022