Home Malware Programs Ransomware RansomMine Ransomware

RansomMine Ransomware

Posted: December 5, 2017

Threat Metric

Threat Level: 10/10
Infected PCs: 7
First Seen: May 18, 2022
Last Seen: August 30, 2022
OS(es) Affected: Windows

The RansomMine Ransomware is a poorly coded file-encryption Trojan whose author has included a disclaimer, which states that the software is meant to be used in a joking matter, and they are not responsible for the damages it may cause. Regardless of being tagged as a joke, you can rest assured that the RansomMine Ransomware is a functional file locker, which has the ability to encrypt the contents of various files on the infected computer swiftly. Thankfully, the author of the RansomMine Ransomware has not coded this threat from scratch and, instead, they have borrowed a significant portion of the code used by the HiddenTear ransomware project. This means that just like many other HiddenTear variants, the RansomMine Ransomware is also decryptable and its victims can rely on a free file recovery utility to get their data back.

The ransom message reveals that the RansomMine Ransomware was intended to be a joke because it does not ask its victims to pay money. Instead, it asks them to play a particular version of Minecraft for an hour, and then the decryptor will get their files back to normal automatically. The contents of the ransom note are written in Korean, and we were unable to locate an English version of the file locker. Instead of using the traditional text-file that most HiddenTear variants use to deliver the ransom note, this threat displays the attacker's message in a new window. The last interesting detail regarding the attack is that all encrypted files will have the '.RansomMine' extension added to their names.

It is almost certain that you will not be infected with the RansomMine Ransomware because the author probably will not aim to spread this file-encryption Trojan. However, if by any chance you get your files locked by this threat, then you should not panic! We can't confirm whether playing Minecraft will get your files back, but we can confirm that you can remove the RansomMine Ransomware's files with the help of a reputable anti-virus application. When this step is complete, you should download and run a free HiddenTear decryption utility that will guide you through the file decryption process.

Loading...