Threat Database Ransomware Wnmd Ransomware

Wnmd Ransomware

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 3
First Seen: December 15, 2021
Last Seen: December 19, 2021
OS(es) Affected: Windows

The Wnmd Ransomware belongs to a threatening class of malware, designed specifically to render the data of their victims unusable and inaccessible. The attackers then aim to extort their victims for money in exchange for providing the decryption key or software tool necessary for the restoration of the files.

During its encryption process, Wnmd marks all impacted files by changing their original names. The threat appends the names with '.wnmd' as a new file extension. When all targeted file types have been locked, a ransom note with instructions will be dropped on the infected systems. The message will be delivered as a newly-created text file named '#INSTRUCTIONS DECRYPT.txt.'

Ransom Note's Details

Wnmd Ransomware's note is rather brief. It states that affected users have to follow only the two steps outlined in the message to gain their files back. The first one is to establish contact with the attackers by messaging the hacker's Discord account. After that, victims will supposedly be given the decryption key. If the note can be trusted, Wnmd Ransomware's operators do not want to receive any payment. Of course, that may not be the case exactly, as the hackers could add multiple new requirements during the private conversion with the victims.

The full text of the note is:

'Ooops…. Your PC Have Been Encrypted.
Your important files are encrypted with a special encryption alogorithm.

How to recover your files?

Step1. To decrypt all your files you need to message me in discord user# i magisa#3409

Step2. After when you will message me i will send you the decryption key!

Sep3. GOOD LUCK 😀'

Trending

Most Viewed

Loading...