Cossy ransomware – a Russian file locking virus which uses the RSA-2048 code to encrypt data

Cossy ransomware is a Russian cryptolocker which uses a unique encryption code to block various documents that are stored on the infected computer. This cyber threat uses RSA-2048 encryption[1] and ads the .Защищено RSA-2048 and .Protected by RSA-2048 appendixes to most of the files, while executables appear with the .lnk.Protected by RSA-2048 extension added. Moreover, Cossy virus brings a file named Cossy.exe from which you can spot the infection. As we can see from the ransom note, this dangerous cryptovirus is mostly targeting Russian-speaking users as the message is written in the Russian language. The crooks have been offering five small files for free decryption and urging for 50 rubles in BTC as the ransom price. After the money is received, they promise to send the decryption tool, however, such promises often appear to be false.
| Name | Cossy |
|---|---|
| Type | Ransomware |
| Appendixes added | .lnk.Protected by RSA-2048 – for executables, .Protected by RSA-2048 and .Защищено RSA-2048 – for other files |
| Encryption algorithm used | RSA-2048 |
| Target | Russian speakers |
| Ransom price | 50 rubles in BTC |
| Given email | grafimatriux72224733@protonmail.com |
| Distribution | Spam messages and their attachments, rogue links, and files, etc. |
| Removal | Delete the virus automatically. Use FortectIntego to detect malware content |
Here is the Cossy ransomware ransom message translated into the English language:
Hello dear friend! Yes, I’m a mean greedy but I have to say it …
forgive …
but …….
all your files ___
SAFE! 1 !! 11 !! 11! 1: DDDDDDDDD
Algorithm RSA! 2048 bits! 4096 too lazy!
It is based on primes it.
I'll tell you just now.
Write to grafimatriux72224733@protonmail.com .
We provide: Free transcript. Paid decryption (and Contractual decryption) *
Contractual decryption is if you have old-time files that have been saved for many years, the decoder is provided free of charge.
Paid decryption costs – 50 rubles in bitcoins, the wallet will be made unique for you. *
You can decrypt 5 files with a size of 5 MB or less for free.
I will not kid you, + give when paying tips to improve the security and deciphering instructions. ”
* – Services provided to us if you write a letter to the file is extremely important infa.RSA-2048 File
The crooks provide grafimatriux72224733@protonmail.com email address as a way to show contact. However, we advise avoiding any relations with the cybercriminals as these people cannot be trusted. Furthermore, you should remove Cossy virus from the computer system permanently. For this purpose, use reliable anti-malware software only. Additionally, we suggest downloading and installing a tool such as FortectIntego to detect all malware-laden content that might be secretly hidden.
Cossy ransomware removal is necessary if wanted to avoid possible damaging consequences. Such cyber threats are capable of many things. For example, modifying the Windows operating system[2] and adding rogue components to it. Furthermore, the ransomware virus can inject dubious entries straight into the Registry. Such changes let the damaging virus to perform its activities and activate the encryption process.
Additionally, Cossy ransomware can inject other malware-related programs, one of which might be a Trojan horse[3] infection. Once your computer is infected with ransomware, its security level decreases and other infections become more capable of entering the system unnoticed. Furthermore, in some case, a ransomware infection can relate in the deactivation of antivirus or firewall security programs. This means, that the virus can operate without being caught.
One more thing you need to know about ransomware viruses is that these threats can encrypt that data which is stored only on the infected computer. Note that, if you decide to keep valuable documents on a remote server, the viruses such as Cossy ransomware will not be able to reach it, unless you keep it plugged often. So, better get rid of the ransomware as soon as you spot encrypted files and manage to take care of your information next time.

Ransomware distribution techniques
According to malware experts,[4] if a ransomware infection has entered your computer system, it can have happened in a few ways. Ransomware viruses are capable of spreading via spam messages and their rogue files, malicious links from third-party websites. Good news, you can avoid this malware, however, you will need to take some actions of your own:
- Avoid opening unknown emails, especially, their rogue attachments. Crooks often drop malware-laden email messages straight to the victims' email boxes. So, be careful while opening emails, make sure they come from recognizable senders.
- Stay away from secondary websites. These pages, especially P2P networks, can lack required protections and include malicious links or files. If you accidentally access such content, your computer system can easily get infected with a ransomware virus.
- Install computer security. Do not be afraid to invest in a reliable antivirus tool. These automatical programs are capable of protecting the system from malicious programs and various computer-related issues.
Get rid of Cossy virus
If the ransomware infection has appeared on your computer, make sure that you get rid of it ASAP. We recommend using a tool such as FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes to detect all components that are related to the cyber threat. Once you remove Cossy virus, make sure that all virus-related content was eliminated successfully. Furthermore, you can perform system backups to disable all active components.
Performing the Cossy ransomware removal requires lots of the user's attention. This is the main reason why the cyber threat cannot be removed manually. If you decide to eliminate the ransomware virus on your own, you can cause even more damage for your computer system or miss some rogue components that might be secretly hidden. Additionally, take a look at our below-provided data recovery steps.
Did this guide help?
Be the first to comment