COCKROACH_LOCKER Ransomware Description
Day after day, cybersecurity experts keep uncovering more ransomware threats in the wild. It would appear that cyber crooks regard creating and distributing file-locking Trojans as a low-risk high-reward endeavor since it is not likely that authorities will ever manage to sniff them out and punish them. One of the latest ransomware threats, which have been spotted, is the COCKROACH_LOCKER Ransomware. It is not yet certain whether this threat belongs to any of the known ransomware families.
Propagation and Encryption
It is not clear what propagation method has been utilized by the authors of the COCKROACH_LOCKER Ransomware. However, there are several techniques, which are very common when it comes to spreading ransomware threats. The most common one is spam emails that contain macro-laced attachments. The user is urged to open the attachment, which contains the unsafe payload of the threat. Another technique that is often used in the propagation of data-locking Trojans is bogus updates for popular applications such as Adobe. When the COCKROACH_LOCKER Ransomware manages to find its way into a system, it will scan its contents. This is done so that the ransomware threat will locate the files, which match the file types it was programmed to target. Usually, ransomware threats are designed to target as many filetypes as possible to ensure maximum damage. When the scan is completed successfully, you will notice that the names of your files have been altered. This data-locking threat adds a ‘.[email@example.com].COCKROACH’ extension at the end of the filenames of the newly encrypted files. This means that a file that was named ‘Albion.jpeg’ originally will be renamed to ‘Albion.jpeg.[firstname.lastname@example.org].COCKROACH’ when the COCKROACH_LOCKER Ransomware completes its encryption process.
The Ransom Note
In the next part of the attack, the COCKROACH_LOCKER Ransomware will drop a ransom note on the desktop of the user. The name of the note is ‘!_HOW_RECOVERY_FILES_!.txt.’ In the note, the authors of the COCKROACH_LOCKER Ransomware inform the victims that their files have been locked, but the damage can be reversed. Then, they give out an email address where they expect the victim to contact them – ‘email@example.com.’ There also is a backup email provided – ‘firstname.lastname@example.org.’ To prove to the victim that they can decrypt the locked data, the attackers offer to unlock three files free of charge, provided that they do not contain any important information. Of course, to receive the decryption key, the attackers demand you to pay a hefty ransom fee.
We would advise you against cooperating with cybercriminals under any circumstances. There is never a guarantee that you will be provided with the decryption key, even if you pay the demanded ransom. Instead, you should for a reputable anti-malware application, which will help you get rid of the COCKROACH_LOCKER Ransomware once and for all.
Do You Suspect Your PC May Be Infected with COCKROACH_LOCKER Ransomware & Other Threats? Scan Your PC with SpyHunterSpyHunter is a powerful malware remediation and protection tool designed to help provide PC users with in-depth system security analysis, detection and removal of a wide range of threats like COCKROACH_LOCKER Ransomware as well as a one-on-one tech support service. Download SpyHunter's FREE Malware Remover
Security Doesn't Let You Download SpyHunter or Access the Internet?Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
- Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
- Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
- Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
- IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.