Home Malware Programs Ransomware TerrorWare Ransomware

TerrorWare Ransomware

Posted: February 8, 2021

TheTerrorWare Ransomware is a low-quality file-locker that was created with the use of the open-source HiddenTear ransomware project. Typically, threats of this type extort the victim for money by encrypting their files and then offering to sell a decryption service. While the TerrorWare Ransomware does have the ability to encrypt files, its ransom note reveals that the criminals might have different plans – they do not ask the victim for a ransom payment and, instead, they ask them to join a specific Discord server. This might mean that the criminals are using the TerrorWare Ransomware to promote their Discord server and increase its membership – however, there also is a chance that users who join may be contacted, and then extorted for money.

TerrorWare Ransomware's attack is recognizable by the extension '.terror' added to locked files. It also drops the ransom message 'READ_ME.txt.' Apart from the Discord link, the note also includes a download link for a 'decryptor' – however, downloading files offered by hackers who just infected you with malware is unlikely to be a good idea. Make sure to first install and run a reputable anti-malware tool that will eliminate the TerrorWare Ransomware. After this, scan the file from the ransom note to see if it is threatening.

If you happen to join the Discord server of TerrorWare Ransomware's creators and they start asking you for a ransom payment, then you should know that trusting them is a terrible idea. Even if you pay up, it is highly unlikely that they will help you. Follow the aforementioned instructions to remove the TerrorWare Ransomware, and see if their decryptor works. If it does not work, then you should run the free 'HiddenTear Decryptor,' which should be able to recover your data.

Loading...