Londec Ransomware

Londec Ransomware Description

There have been new ransomware threats popping up daily, and malware researchers are struggling to keep up. Among these brand-new file-encrypting Trojans is the Londec Ransomware. Upon dissecting the Londec Ransomware cybersecurity experts determined that it is a variant of the STOP Ransomware.

Propagation and Encryption

It has not yet been uncovered what the propagation methods involved in the spreading of the Londec Ransomware are. Some researchers speculate that the creators of the Londec Ransomware may be using mass spam email campaigns, fraudulent software updates, and pirated fake copies of legitimate applications may be some of the infection vectors used by the cyber crooks. When this ransomware threat worms its way into your computer, it will perform a brief scan. The goal is to locate your files, which the Londec Ransomware was programmed to target. Then, the Londec Ransomware will trigger its encryption process. When the Londec Ransomware locks a file, its name will be altered. The Londec Ransomware adds a '.londec' extension at the name of the file. For example, if a photo was originally named 'Lost-Marine.jpeg' will have its name altered to 'Lost-Marine.jpeg.londec.'

The Ransom Note

The ransom note that the Londec Ransomware is called '_readme.txt' and states:


Don’t worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don’t get answer more than 6 hours.

To get this software you need write on our e-mail:

Reserve e-mail address to contact us:

Our Telegram account:
Mark Data Restore

Your personal ID:’

In the note, the attackers ask for a ransom fee of $890. They also claim that users who get in touch with them within 72 hours of the attack taking place will get a 50% discount and the price will drop to $490. The authors of the Londec Ransomware provide two email addresses where they can be contacted – 'gorentos2@firemail.cc' and 'gorentos@bitmessage.ch.' The attackers also give out their Telegram contact details @datarestore.

Stay away from cyber crooks like the ones responsible for the Londec Ransomware. Such individuals are not to be trusted. A safer option is to download and install a reputable anti-malware tool and use it to wipe off the Londec Ransomware from your PC.