Home Malware Programs Ransomware GottaCry Ransomware

GottaCry Ransomware

Posted: May 27, 2019

Ransomware operators are not always experienced cybercriminals who are experts when it comes to writing malware. The authors of the GottaCry Ransomware are the most recent proof of that – their so-called ‘file-locker’ is unable to encrypt any files on the targeted computer, but it still attempts to extort its victims for money by telling them they can purchase a decryptor in exchange for $50 (paid via Bitcoin) or $70 (paid via PayPal).

While the GottaCry Ransomware does not encrypt files, it will not leave the compromised system unharmed – some of its code is meant to wipe out the contents of the ‘Desktop’ folder. Unfortunately, it is impossible to guarantee the recovery of these files, since they are deleted permanently – some file recovery tools might be able to undo some of the damage, but they are unlikely to bring all files back.

The attackers have supplied their Discord username as the only way to get in touch with them and get a decryption password in exchange for money – you should not contact them! Restoring your computer to normal can be done by using an anti-virus scanner to dispose of the GottaCry Ransomware. However, as we mentioned above, this will not get the deleted files back, and you will need to try to find alternative data recovery options.

Loading...