• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

The “Ssimpotashka @gmail.com” Ransomware

July 19, 2018Simeon Georgiev

Ransomware removal experts have found yet another ransomware knocking on the door. It’s known by its email address ssimpotashka @gmail.com and is inspired from Scarab Ransomware, to which it bears many similarities. It has been operating since May but only detected recently by ransomware removal experts.

Ransomware removal experts think that the authors of the Scarab Ransomware have managed to create a RaaS (Ransomware-as-a-Service) application and deployed it into the Deep Web where a cybercriminal group managed to modify it as [email protected]. Deep Web or Dark Web is an illegal market place that can only be viewed through TOR browser and acts as the leading platform for the most dangerous cybercriminals.

Analysis of Ssimpotashka @gmail.com Ransomware

Like other ransomware of this kind, the ‘ssimpotashka’ ransomware enters a computer system stealthily and starts working before users can detect it. The virus deletes its components once it manages to encrypt users’ files. This is the reason it is hard for anti-ransomware tools to discover it.

The ransomware particularly targets the Temp folders in the computers and proceeds to encrypt videos, audios, text files, office documents and database records. The ‘ssimpotashka’ also manages to modify the extension of encoded files to its own extension “[email protected]”.

The malicious encryption of files is followed by a ransom note, notifying that the files of the users are now encrypted. A unique ID is given to the victims for future communication. Further communication is encouraged through the email [email protected]. Victims are asked to pay a ransom in exchange for return of their files to their original state and also to remove ransomware.

In order to demonstrate their hold over the data, the hackers offer to decrypt any three unimportant files. The message ends with a warning to refrain from using any anti-ransomware software as well as a reminder to pay the ransom in two days. Failure to accept ransom demands is threatened with irreparable loss of data.

The ransomware usually spreads through malicious email attachments. P2P services like Torrent are also one of the medium used by these hackers.  Moreover, the ransomware is also part of several fake software installers available on the internet.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Infecting through a Ransomware or Mining Virus – Malware Becomes Smart Next post First Ransomware Attack – Where Did It All Begun?

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Ransomware: 4 Types of the Latest Trend in Cybercrimes

February 1, 2018Simeon Georgiev
Ransomware: 4 Types of the Latest Trend in Cybercrimes

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.