Ransomware identification
How to identify a ransomware group?
How to identify the ransomware group?
During a ransomware attack, cybercriminals usually leave a ransom note in English text format, indicating the steps to follow to decrypt the data.
Readme.TXT
“We are XXX.
Your company’s servers are locked, and data has been taken to our servers. This is serious.
Good news:
your server system and data will be restored using our decryption tool;
for now, your data is safe and stored securely on our server;
nobody in the world knows about your company’s data leak, except you and the XXX team.”
If the hacker group is not specified, you can use a specialized platform to identify it. You just need to upload the TXT file there.
If you are infected by ransomware, here are a few warning signs that can alert you:
- Modification of file extensions: Ransomware generally encrypts your files and changes their extension. For example, a file named "photo.jpg" could be renamed as "photo.jpg.locky".
- Increase in processor activity: Ransomware can cause an increase in processor activity while encrypting your files.
- Suspicious activity on your computer: If your computer behaves unusually, for example, if programs close by themselves or if your system is slower than usual, this could be a sign of a ransomware infection.
- Ransom notes: Ransomware generally displays a ransom note on your screen once your files have been encrypted. This request can appear as a pop-up window or as a text file placed in your folders.
Please note that while these signs may indicate a ransomware infection, they can also be the result of other IT issues. If you suspect a ransomware infection, we recommend contacting us.
Ransom notes: the ransom request from cybercriminals
When your computer or network falls victim to a ransomware attack, you often find yourself facing an enigmatic message: the ransom note. This text, frequently written in multiple languages, serves as a true calling card for the cybercriminal. It informs you that your files have been encrypted and that you must pay a ransom to recover them.
What does a ransom note look like?
Ransom notes can take different forms, but they generally contain the following elements:
- A catchy title: to grab your attention and put you on high alert.
- A clear (or vague) explanation: cybercriminals explain, in more or less detail, how your files were encrypted and why you must pay.
- The ransom amount: often expressed in cryptocurrencies (Bitcoin, Ethereum…) to guarantee the anonymity of the payment.
- A deadline: cybercriminals set a time limit for paying the ransom, after which the amount may increase or the files may be permanently lost.
- Instructions: they provide details on how to contact them to make the payment.
Why do cybercriminals use ransom notes?
Ransom notes serve several purposes:
- Inform the victim: cybercriminals want you to know that your files are compromised and that you need to take action.
- Create pressure: by setting a deadline and threatening to delete the files, they hope you will pay quickly.
- Extort money: of course, their ultimate goal is to extort money from you.
See also: our dedicated page on ransomware decryption.