Threat Database Ransomware Lizard Squad Ransomware

Lizard Squad Ransomware

The Lizard Squad Ransomware threat is designed to encrypt the data found on any breached devices specifically. The malware initiates an encryption routine that uses a sufficiently strong cryptographic algorithm so that victims will be unable to easily restore their files. The attackers then attempt to extort money from the affected users or companies. The Lizard Squat, in particular, appears to be targeting mostly Chinese-speaking users.

Whenever the ransomware encrypts a file, it also will append a random four-character string to the file's name as a new extension. When all targeted file types - documents, PDFs, archives, photos, databases, etc., have been encrypted, the Lizard Squad will proceed to create a text file named '說明it.txt.' Inside the file, victims will find a ransom note written in Chinese, as well as an English translation. In addition, the threat also will change the current desktop background image with a new one.

According to the message of the note, the cybercriminals demand to be paid a ransom worth 2000 USDT-TRC20 crypto-coins. This means that the hackers will accept payments made only with Tether’s cryptocurrency issued on the TRON network. After transferring the money, victims are instructed to contact the threat actors by sending a message to the provided email address at '' or Telegram account at '@woo090909.'

The full text of the ransom note left by Lizard Squad Ransomware is:



'I'm from an international organization called: Lizard Squad
we are a hacker group
My name is: Mr. 09
I will use your computer as collateral for collection

Please pay: USDT-TRC20
Amount: 2000
Payment address: TRZRAM9KL5qv1BMrXxo876wetHfzT19sii
contact details :
telegraph: @woo090909
Contact me after payment and I will unlock it for you
If you do not pay, your computer and files will be automatically destroyed,
If you really want a fix, feel free to pay the fee, contact me and I'll consider giving you a discount.'


Most Viewed