The Prandel Ransomware is among the newest ransomware threats that were spotted by cybersecurity researchers recently. Some cybercriminals that are more tech-savvy build their own data-locking Trojans while others rely on already existing threats. Such is the case of the Prandel Ransomware. This ransomware threat is a variant of the very popular STOP Ransomware.

Propagation and Encryption

Malware experts have been unable to tell the exact methods of propagation that the creators of this ransomware threat are using. It appears that the authors of the Prandel Ransomware may have used mass spam email campaigns, bogus software updates, and pirated fake copies of popular applications as infection vectors to spread their creation. Once the Prandel Ransomware manages to compromise a system, it will begin the attack by scanning the files present swiftly. The purpose of the scan is to locate the files, which will then be targeted for encryption. Next, the Prandel Ransomware will begin locking the files. When a file undergoes the encryption process of the Prandel Ransomware, its name will be changed. This ransomware threat adds a '.prandel' extension at the end of the filename of the newly locked file. For example, if you had a file called 'my-half-blood-prince.jpeg,' its name will be altered to 'my-half-blood-prince.jpeg.prandel' after the encryption is completed.

The Ransom Note

Then, the Prandel Ransomware will proceed with the attack by dropping a ransom note named '_readme.txt.' The note reads:


Don’t worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don’t get answer more than 6 hours.

To get this software you need write on our e-mail:

Reserve e-mail address to contact us:

Our Telegram account:
Mark Data Restore

Your personal ID:’

As you can see, the authors of the Prandel Ransomware demand $980 as a ransom fee. They also state that victims that contact them within 72 hours will be given a 50% discount and thus will have to pay $490 instead of the full price. The attackers provide their victims with two email addresses – '' and '' In case the user prefers to converse over Telegram, they have given out their Telegram contact details too - @datarestore.

We strongly recommend not paying cybercriminals. It also is better if you ignore their demands completely and instead download and install a legitimate anti-spyware tool, which will wipe off the Prandel Ransomware from your computer. Then, you can attempt to recover some of the lost files via a third-party data-recovery solution.


