Pqgs Ransomware

Pqgs Ransomware Description

Cybercriminals have unleashed another threatening ransomware variant based on the STOP/Djvu malware family. The new threat is being tracked as the Pqgs Ransomware by infosec researchers. It possesses all of the capabilities associated with this family of threats - it targets a large number of file types, renders them inaccessible via an encryption process, and the used cryptographic algorithm is strong enough to make the restoration of the victim's data without having the specific decryption key not realistic.

As part of its unsafe operations, the threat also will mark all locked files by appending '.pqrs' to their original names as a new file extension. As for the note with instructions of the victims, it will be dropped onto the compromised system as a text file named '_readme.txt.'

Ransom Note's Details

The Pqgs Ransomware demands its victims to pay exactly $930 if they want to receive the decryption key and software tool from the attackers. The threat also makes the typical STOP/Djvu offer to cut the demanded price in half if the affected users reach out and establish contact with the hackers within the first 72 hours of the malware infection.

The note mentions two email addresses that can be used as communication channels - 'manager@mailtemp.ch' and 'helprestoremanager@airmail.cc.' Victims are also supposedly allowed to attach one locked file to their message. The hackers then promise to unlock and return it for free.

Generally, it is not a good idea to trust ransomware operators or any other type of cybercriminals. There are no guarantees that the attackers will keep their end of the deal. Furthermore, any money they receive could be used to fund their next malicious operation. Other dangerous ransomware threats include Chichi, HELPME, Qdla and more.

The full text of Pqgs Ransomware's note is:

'ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-ZmofmHikRP
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
manager@mailtemp.ch

Reserve e-mail address to contact us:
helprestoremanager@airmail.cc

Your personal ID:'