Threat Database Ransomware AB89 Ransomware

AB89 Ransomware

By GoldSparrow in Ransomware

The AB89 Ransomware is a threatening encrypting tool that locks up files on targeted machines and demands a ransom to unlock them. The AB89 Ransomware belongs to the Matrix Ransomware family. The AB89 Ransomware modifies the names of the affected files – the original name is replaced with the threat actors’ email address AdamBrown89@criptext.com. A string of random characters is then added to the email address, followed by the "AB89" extension. A text file name "AB89_INFO.rtf," which contains the ransom note, is dropped in every folder.

This ransom note states that the attackers have used the AES-256 and RSA-2048 encryption algorithms to lock up the victim’s data. The message also says that the user needs to contact the hackers at one of these three email addresses: AdamBrown89@criptext.com, AdamBrown89@aol.com, and AdamBrown89@tutamail.com to get instructions on how to pay the ransom, and, respectively, buy the decryption key. The AB89 Ransomware operators also offer to decrypt three files for free to persuade the victim that they have the needed key.

To avoid a ransomware infection, users should never open emails and attachments from unknown senders. Visiting torrent websites or clicking on suspicious advertisements also can result in malware being installed on their computers.

Trending

Most Viewed

Loading...