NOBAD ransomware – a file locker that uses AES and RSA to encrypt all personal data on the infected computer

NOBAD virus is the newest addition to the Matrix ransomware family. It was first spotted in the wild mind-October using AES-128 + RSA-2048 encryption algorithms[1] to encrypt data by adding .NOBAD file extension. The main goal of crypto-viruses is to extort money out of victims by blackmailing them and asking for a ransom for the locked file decryptor. Cybercriminals provide a lengthy ransom note #NOBAD_README#.rtf in order to make sure that users are aware of what happened, and what they should do next. NOBAD ransomware authors explain that victims need to pay ransom in Bitcoin and contact them using nobad@tutamail.com email.
| SUMMARY | |
| Name | NOBAD |
| Type | Ransomware |
| Variant of | Matrix ransomware |
| Ciphers used | AES-128 + RSA-2048 |
| File extension | [email].[random_combination].NOBAD |
| Ransom note | #NOBAD_README#.rtf |
| Distribution | Unprotected RDP, exploit kits, fake updates, spam emails, etc. |
| Elimination | Download and install FortectIntego for virus elimination |
NOBAD ransomware is known to break in through the unprotected RDP configuration,[2] same as latest variants of Matrix – KOK08, ITLOCK, and EMAN do. Hackers perform a special scan where poorly protected systems using Remote Desktop Protocol are detected. They then brute-force the attack and install NOBAD virus remotely.
Additionally, NOBAD ransomware is also known to be spread using phishing emails, as well as exploit kits like RIG or EITest. No matter how the virus entered, the infected users should immediately take care of NOBAD ransomware removal. While manual elimination is not recommended, users can make use of professional security software like FortectIntego and get rid of the infection automatically.
NOBAD ransomware shuts down and spawns certain Windows processes in order to function. It modifies Windows Registry to ensure persistence, deletes Shadow Volume Copies and scans the PC for video, audio, database, image, and other personal files to encrypt them. If modifies files the following way: [email].[random_combination].NOBAD. This means that a file called picture.jpg will be turned into something like nobad@tutamail.com.hjg68TisG-Bsa7aV.NOBAD, rendering it unusable.
Victims are then baffled – they are left with one of the two options: either pay the ransom or lose all personal data. Proceeding with the payment is definitely not the option users should pick, as money loss is highly likely (criminals can simply not provide the key, and keep the money). Instead, they should remove NOBAD ransomware and recover files using backups. Alternatively, third-party applications can be helpful as well – check the instructions below.

Ransomware can infiltrate your PC easily if you do not take adequate protection measures
Malware authors seek to spread the virus to as many computers as possible, as it makes a perfect illegal business. Unsurprisingly, ransomware has been the most prominent and damaging cyber threat of 2017, and, while crypto mining malware is also establishing itself well, ransomware is here to stay, and users, as well as organizations, should take care of their computer safety.
There are several ways ransomware can compromise the PC, including:
- Breaking through via the poorly protected RDP
- With the help of spam emails
- Abusing software vulnerabilities
- Using exploit kits
- Infiltrating as a drive-by download, etc.
While there is no means of 100% online protection, precaution measures can make a significant difference and reduce the infection rate drastically. According to experts,[3] users should always pay attention to suspicious emails, as the link or attachment inside can carry the malicious payload.
Using strong passwords, updating all installed programs on time, using an up-to-date security software with the real-time feature can significantly reduce the chance of ransomware infection. Additionally, keeping backups on the cloud or remote server is always a good idea.
Eliminate NOBAD ransomware using comprehensive anti-virus software
NOBAD ransomware removal might not be that easy, especially for those who never had to deal with cyber infections before. One thing is clear: users should not delay the process, as it might indicate multiple infections on the machine.
Thus, download anti-malware software, such as FortectIntego and perform a full system scan. Be aware that the virus might prevent security software from operating correctly. In such a case, enter Safe Mode with Networking and remove NOBAD virus safely. Only after the elimination procedure you can go ahead and attempt file recovery. In case you did not keep any backups, check for alternative options below.
Was this guide helpful?
Be the first to comment