Ransomware identification

How to identify a ransomware group?

How to identify the ransomware group?

During a ransomware attack, cybercriminals usually leave a ransom note in English text format, indicating the steps to follow to decrypt the data.

				
					Readme.TXT
“We are XXX.
Your company’s servers are locked, and data has been taken to our servers. This is serious.
Good news:

your server system and data will be restored using our decryption tool;

for now, your data is safe and stored securely on our server;

nobody in the world knows about your company’s data leak, except you and the XXX team.”
				
			
 

If the hacker group is not specified, you can use a specialized platform to identify it. You just need to upload the TXT file there.

If you are infected by ransomware, here are a few warning signs that can alert you:

Please note that while these signs may indicate a ransomware infection, they can also be the result of other IT issues. If you suspect a ransomware infection, we recommend contacting us.

Ransom notes: the ransom request from cybercriminals

When your computer or network falls victim to a ransomware attack, you often find yourself facing an enigmatic message: the ransom note. This text, frequently written in multiple languages, serves as a true calling card for the cybercriminal. It informs you that your files have been encrypted and that you must pay a ransom to recover them.

What does a ransom note look like?

Ransom notes can take different forms, but they generally contain the following elements:

  • A catchy title: to grab your attention and put you on high alert.
  • A clear (or vague) explanation: cybercriminals explain, in more or less detail, how your files were encrypted and why you must pay.
  • The ransom amount: often expressed in cryptocurrencies (Bitcoin, Ethereum…) to guarantee the anonymity of the payment.
  • A deadline: cybercriminals set a time limit for paying the ransom, after which the amount may increase or the files may be permanently lost.
  • Instructions: they provide details on how to contact them to make the payment.

Why do cybercriminals use ransom notes?

Ransom notes serve several purposes:

  • Inform the victim: cybercriminals want you to know that your files are compromised and that you need to take action.
  • Create pressure: by setting a deadline and threatening to delete the files, they hope you will pay quickly.
  • Extort money: of course, their ultimate goal is to extort money from you.

See also: our dedicated page on ransomware decryption.