Threat Database Ransomware Dev0 Ransomware

Dev0 Ransomware

Users infected with the Dev0 Ransomware will find that nearly all of their files have been rendered inaccessible. The Dev0 Ransomware is a threat classified as belonging to the Makop malware family. The goal of the hackers behind Dev0 is to then extort their victims for money in exchange for restoring the encrypted data. Each locked file will have its name changed drastically. The threat places an ID number unique to the victim, an email address, and a new file extension at the end of the original filenames. The email is 'xdatarecovery@msgsafe.io' while the new extension is '.dev0.'

The ransom note of the Dev0 Ransomware is delivered in the form of 'readme-warning.txt' text files that are placed inside all folders containing locked data. The note doesn't mention the exact amount of the ransom demanded by the hackers. It does specify that the money must be transferred using the Bitcoin cryptocurrency. In addition, users must reach out via two email addresses found inside the note - xdatarecovery@msgsafe.io or bobwhite@cock.li. Up to two simple files (jpg, Xls, doc and similar extensions) that do not exceed 1MB in size can be attached to the email message. The hackers promise to decrypt the files and send them back unlocked.

While dealing with a ransomware threat can be extremely stressful, users still have options that do not involve exposing themselves to additional security threats by contacting the cybercriminals. Instead, use a professional security product to clean the compromised system and then look for a suitable backup.

The ransom note delivered by Dev0 Ransomware is:

'::: Greetings :::

Little FAQ:
.1.
Q: Whats Happen?
A: Your files have been encrypted and now have the "dev0" extension. The file structure was not damaged, we did everything possible so that this could not happen.

.2.
Q: How to recover files?
A: If you wish to decrypt your files you will need to pay in bitcoins.

.3.
Q: What about guarantees?
A: Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will cooperate with us. Its not in our interests.
To check the ability of returning files, you can send to us any 2 files with SIMPLE extensions(jpg,xls,doc, etc… not databases!) and low sizes(max 1 mb), we will decrypt them and send back to you. That is our guarantee.

.4.
Q: How to contact with you?
A: You can write us to our mailbox: xdatarecovery@msgsafe.io or bobwhite@cock.li

.5.
Q: How will the decryption process proceed after payment?
A: After payment we will send to you our scanner-decoder program and detailed instructions for use. With this program you will be able to decrypt all your encrypted files.

.6.
Q: If I don’t want to pay bad people like you?
A: If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause only we have the private key. In practice - time is much more valuable than money.

:::BEWARE:::
DON'T try to change encrypted files by yourself!
If you will try to use any third party software for restoring your data or antivirus solutions - please make a backup for all encrypted files!
Any changes in encrypted files may entail damage of the private key and, as result, the loss all data.
'

Trending

Most Viewed

Loading...