Threat Database Ransomware Nvetud Ransomware

Nvetud Ransomware

By GoldSparrow in Ransomware

The Nvetud Ransomware is a data-locking Trojan, which has been uncovered by malware experts recently. They dissected this threat and determined that it is a variant of the infamous STOP Ransomware.

Propagation and Encryption

Malware experts cannot determine what the exact infection vector used in the spreading of the Nvetud Ransomware is. It is likely that the creators of the Nvetud Ransomware may have used spam emails containing macro-laced attachments, fake application updates, and pirated bogus copies of legitimate software to propagate their file-encrypting Trojan. When the Nvetud Ransomware gains access to your system, it will perform a scan quickly, which is meant to locate all the data that this threat was programmed to target. Then, the Nvetud Ransomware will start encrypting the targeted files. Once a file has undergone the encryption process of the Nvetud Ransomware its name will be changed. The Nvetud Ransomware appends a ‘.nvetud’ extension to the newly locked files’ names. For example, an audio file called ‘My-American-Boy.mp3’ will be renamed to ‘My-American-Boy.mp3.nvetud’ and will no longer be playable.

The Ransom Note

The Nvetud Ransomware drops a ransom note called ‘_readme.txt,’ which reads:


Don’t worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don’t get answer more than 6 hours.

To get this software you need write on our e-mail:

Reserve e-mail address to contact us:

Our Telegram account:
Mark Data Restore

Your personal ID:’

In the note, the authors of the Nvetud Ransomware claim that they demand a $980 ransom fee but the users that contact them within 72 hours of the attack will get a 50% discount and the price will be knocked down to $490. The attackers give out two email addresses where they expect to be contacted – ‘’ and ‘’ If the victim prefers Telegram, they also provide their Telegram details @datarestore.

We counsel you to stay away from cyber crooks like the creators of the Nvetud Ransomware. Such shady individuals rarely keep their promises. Instead, you should obtain a reputable anti-virus application, which will remove the Nvetud Ransomware from your computer safely. Then you can try to restore some of the lost data using a third-party file-recovery application.


Most Viewed