Threat Database Ransomware Dark Ransomware

Dark Ransomware

The Dark Ransomware threat is a variant belonging to the infamous VoidCrypt malware family. Although the threat doesn't seem to have evolved beyond a simple variant when compared to other members of the VoidCrypt Ransomware family, this fact in no way diminishes its capacity to disrupt any infected devices. When activated on the targeted system, the Dark Ransomware will run an encryption routine that will lock a wide array of file types. Indeed, affected users will discover that their documents, PDFs, archives, databases, photos, and more, are no longer accessible.

In addition, each encrypted file will have its name changed drastically. The threat will first add an ID string generated specifically for the victim. Then it will append the 'Darksight@tutanota.com' email address followed by '.dark' as a new file extension. A new text file will also be dropped on the desktop of the breached device. The file will be named 'unlock-info.txt' and inside it, victims will find a ransom note with instructions.

The message left by the cybercriminals states that the hackers will accept ransom payments made using the Bitcoin cryptocurrency only. Victims are expected to establish contact by messaging either the email found in the names of the encrypted files or a reserve address at 'darksight@mailfence.com.' The threat actors seem to be willing to decrypt one file for free. However, victims should choose a file that is less than 1MB in size and it shouldn't contain any important information.

The full text of Dark Ransomware's message is:

'All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail; Darksight@tutanota.com
Write this ID in the title of your message : -
In case of no answer in 24 hours write us to theese e-mails: darksight@mailfence.com
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.

Free decryption as guarantee
Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
'

Related Posts

Trending

Most Viewed

Loading...