Threat Database Ransomware Decryption#1222 Ransomware

Decryption#1222 Ransomware

Cybersecurity researchers have uncovered the existence of a ransomware threat tracked as the Decryption#1222 Ransomware. The malware is used in attack operations, aimed at rendering the data found on the breached devices completely unusable. Victims' files will be locked via an uncrackable encryption routine. The attackers will then try to extort the affected users for money, in exchange for assisting them in the restoration of the valuable data.

Unlike most ransomware threats that try to avoid encryption of essential files as that could cause critical system errors and system instability, Decryption#1222 is likely also to lock executable files. Each locked file will be marked by having '.n53yb34tbb2' appended to its original name. The threat also will create a text file named 'HOW TO DEYCRYPT.txt' on the breached systems. The file will contain a ransom note with instructions from the hackers.

Ransom Note's Details

The ransom-demanding message of the Decryption#1222 Ransomware reveals more peculiar details. For example, the only way to establish contact with the attackers is by messaging a Discord user under the account name 'decryption#1222.' Affected users also will be asked to provide various other details, such as their personal id, computer name, username and possibly more. The note also states that victims will have to pay a ransom of $500, or $400 if they are 'kind,' whatever that means. The money must be transferred to the crypto-wallet address provided by the cybercriminals, with the only accepted payment option being the Bitcoin cryptocurrency, 

The full text of Decryption#1222 Ransomware's note is:

'Hello! All your files have been encrypted...

To decrypt your files you need to write to decryption#1222 on DISCORD

THE ONLY WAY TO GET YOUR FILES BACK IS TO PAY $500 IN BITCOIN TO THE ADDRESS decryption#1222 SENDS YOU

YOU MUST HAVE PROOF OF SENDING THE BITCOIN TO GET YOUR FILES BACK!

Do not try to restore files without our help, this is useless, and can destroy your data permanently. If you are kind, the fee will be only $400....

As .exes are encrypted, please do this from your phone/tablet.

*IMPORTANT!*

Please send all of these, personal id, computername, username, ect. to decryption#1222.'

Trending

Most Viewed

Loading...