Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 3
First Seen: June 10, 2016
Last Seen: June 12, 2022
OS(es) Affected: Windows

Payms Ransomware is an updated variant of Jigsaw Ransomware, which utilizes the same aggressive methods to encrypt files and then hold a system’s files for a substantial ransom fee. Payms Ransomware may be spread through spam message attachments where it automatically loads upon opening the attachment zip file. When loaded, Payms Ransomware will actively start encrypting files and then display a notification that you must pay a fee in Bitcoin that equals about $140 to $225USD to obtain a decryption key to restore all encrypted files. We have noticed that Payms Ransomware is written in both Spanish and English, potentially to target other countries that primarily speak Spanish. Removal of Payms Ransomware may be done to prevent file encryption but must be done promptly by using an antimalware program.

