AngryKite ransomware alters the system and shows a scary message to victims
AngryKite virus seems to be yet another unoriginal ransomware[1], this time based on KRider ransomware virus. The main executable of this virus is angryKite_v3.exe.bin. Once in the computer system, the ransomware encrypts files found on the system (excluding some system files in order to keep the computer running). During the data encoding process, virus replaces the original filename with a random set of characters also adds .NumberDot extension at the end of it. As a result, the victim is left out with a bunch of encrypted files[2] that cannot be opened or manipulated in any way, besides, there is no way to understand which file is which, since the virus entirely corrupts their filenames.
| Name | AngryKite ransomware |
|---|---|
| Type | Cryptovirus |
| Extension | .NumberDot |
| Purpose | Trick people into calling the number that reroutes to criminals asking for money |
| Distribution | Malware spreads using malicious emails and attachments or direct dangerous sites |
| Elimination | Remove the virus with the help of the guide below or an anti-malware application |
| Repair | Make sure to repair damage with a proper tool like FortectIntego |
What is interesting about the virus is that it is a tech-support-scam[3] type of virus. We have noticed that tech support scammers have employed ransomware-type viruses to attack victims and force them to communicate with scammers directly[4]. Actors behind AngryKite ransomware project might expect victims to buy some useless malware removal programs or pay for services “required to fix the computer.”
It is very likely to happen because the virus is programmed to launch a “Warning” window on the computer screen right after encrypting data stored on the computer. The suspicious warning says that “System may have found anonymous encryption on your computer. You would not be able to access the files on your computer.”
The warning also states that “Your system has encryption ransomware which may permanently encrypt your data.” Seeing such a message on the screen can make anyone freak out, however, there’s also some hope to improve the situation – the message suggests calling a provided number “to avoid further damage.” The number associated with this ransomware is 1-855-545-6800.

Our researcher called this number and was greeted with an auto-message “Your call is very important to us. Please stay on the line, and you will be transferred to the next available agent.” Surprisingly, the line was very busy, and we weren’t able to get more information on what scammers say to the victims.
However, if your computer was infected with ransomware, you should remove AngryKite virus right away. Do not listen to scammers who are trying to swindle money from you after illegally installing malware on your computer. For the removal, we strongly suggest using software like MalwarebytesMalwarebytes or SpyHunterCombo Cleaner. Before you start, reboot your PC according to the instructions provided below in the article.
Malware spreading ways
There are many ways how criminals distribute ransomware viruses, for example, they prepare a malicious code and inject it into a Word or JavaScript file[5], and then deliver this file to thousands of targets via email. In other words, scammers use the malspam technique. However, there are more ways to get infected with ransomware.
Some criminals employ more sophisticated ransomware distribution techniques that rely on exploit kits, malware-laden ads, and the like. In order to protect yourself from such attacks, one needs to set up a good anti-malware software system on the computer, update all programs to their latest versions (continuously!), and stay away from hazardous Internet websites while browsing the world wide web.
Get rid of this ransomware virus
Researchers say that this ransomware virus might be decryptable, so do not lose your hopes yet. If these expectations appear to be true, victims will successfully decrypt their files for free. That is very rare to have criminals release the decryptor even after payment.
However, we need to have some patience and wait for more information from malware researchers. Until then, we strongly advise you to remove the virus. You can successfully get rid of the virus with the help of AngryKite removal instructions provided down below. Also, told like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes can help you do that.
Was this guide helpful?
4 comments