Threat Database Ransomware Qmak Ransomware

Qmak Ransomware

Cybercriminals have released a new variant based on the infamous STOP/Djvu Ransomware family of threats. Named Qmak Ransomware, this new threat is equipped with all the threatening capabilities associated with this malware family. It targets a wide range of file types and renders them completely unusable via a strong encryption algorithm. Victims are then extorted for money if they want to restore their personal or business-related data.

During its encryption process, the Qmak Rasomaware marks each affected file by modifying its original file name. As a result, victims will notice that most of the files stored on the breached machine now have '.qmak' as a file extension. In addition, the threat will deliver its ransom note containing instructions for the victims. The ransom-demanding message will be dropped on the system as a text file named '_readme.txt.'

Qmak Ransomware's Demands

Qmak doesn't deviate from the typical ransom message used by STOP/Djvu threats. It states that its victims will have to pay exactly $980 to the attackers to receive the decryption key and software tool necessary to unlock the files. The offer to reduce the ransom amount in half is also mentioned. The specified requirement is for the victims to have contacted the hackers within the first 72 hours of the ransomware attack.

Affected users also are allowed to send a single encrypted file to the cybercriminals who promise to unlock and return it for free. However, the file must not contain any valuable information. The two email addresses that victims can use as communication channels are
'manager@mailtemp.ch' and 'helprestoremanager@airmail.cc.'

The full text of Qmak Ransomware's note is:

'ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-W7mpKFSSv2
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
manager@mailtemp.ch

Reserve e-mail address to contact us:
helprestoremanager@airmail.cc
Your personal ID:
'

Trending

Most Viewed

Loading...