Home Malware Programs Ransomware Verrouille Ransomware

Verrouille Ransomware

Posted: March 29, 2017

Threat Metric

Threat Level: 8/10
Infected PCs: 7,221
First Seen: March 29, 2017
Last Seen: June 23, 2022
OS(es) Affected: Windows

The Verrouille Ransomware (or 'Locked' Ransomware) is a Trojan that tries to ransom your files by encrypting them and selling you the decryption solution. Symptoms of its attacks can impede other recovery actions by locking you out of other software or the Windows user interface. Numerous anti-malware products should be able to remove the Verrouille Ransomware after detecting it immediately, even though recovering all locked files may require a remote backup or other solutions.

Trojans Putting Time Pressure on Again, and Again

The relative success of the Jigsaw Ransomware and its fellow variants is leading to threat actors experimenting with similar ways of pressuring their victims with a limited time to respond. While not a direct relative, the new Verrouille Ransomware uses similar social engineering tactics to coerce you into paying money to unlock your files and desktop. PC users who choose to ignore the Verrouille Ransomware's warnings and take no further actions may find that the contents of their PCs are being deleted, one file at a time.

Malware experts have seen different releases of the Verrouille Ransomware in both French and English, although some samples show evidence of a buggy behavior, such as server networking errors. Working versions of the Verrouille Ransomware will encrypt files on your PC based on either their formats, such as DOC, or their locations, such as the Users directory. The Verrouille Ransomware, then, generates a semi-interactive pop-up showing its ransom demands for your encoded and unusable files.

Both language versions of the Verrouille Ransomware show the same message: instructions for purchasing and transferring Bitcoins to the threat actor, after which you can click on the window's 'verify' button to remove the threat and decode your media. Malware experts also are seeing a companion message alongside the ransom demand that forms the Verrouille Ransomware's most distinctive feature: a ten-minute timer. The Verrouille Ransomware deletes an arbitrary encrypted file every time this cycling countdown hits zero.

Opting out of Your Ten-Minutes Penalty

With the long-term safety of your files being up to responding quickly to extortion, and the rest of your PC's UI blocked by its message window, the Verrouille Ransomware locks down the infected system for profit efficiently. Malware analysts recommend defeating this increasingly common combination of attacks and social engineering manipulation by disabling the Verrouille Ransomware, such as by rebooting directly from your USB drive, before taking other recovery steps.

The anti-malware sector often develops freeware tools that can decrypt major families of file-encrypting Trojans like the Verrouille Ransomware. Despite that possibility, the Verrouille Ransomware is still under investigation for the possibility of decoding, which always is inferior in reliability, compared to having a backup available. Only fully delete the Verrouille Ransomware with your anti-malware software of choice after making a decision about how you intend to save any encrypted content. In the meantime, most security solutions can quarantine the Verrouille Ransomware safely.

With this Trojan's linguistic features taking precedence over the integrity of its remote ransom-tracking servers apparently, the Verrouille Ransomware's authors may be getting ahead of themselves. Readers can hope that this campaign will stay buggy, but should back up their files, regardless.

Related Posts

Loading...