259 ransomware is a data-locking malware that is designed to prevent all data access until ransom is paid

259 virus is a malicious program that stems from a broad malware family known as Dharma ransomware. Spotted in late October 2020, it locks all videos, pictures, music, pictures, documents, and other personal files with the AES (in some cases, DES + RSA) encryption algorithm,[1] appending .[259461356@qq.com].259 extension in the process. Suchlike files lose their original icons and can no longer be accessed.
There are two ransom notes that 259 ransomware delivers:
- a pop-up window titled “259461356@qq.com” – it shows up as soon as data encryption is finished;
- a text file “FILES ENCRYPTED.txt,” which can be opened by any text-editing program (usually, Notepad).
In these notes, the attackers indicate that victims need to pay for decryption in Bitcoins, although the precise sum is not specified. They also attempt to discourage users from using alternative methods to recover .259 files, as it may cause permanent damage to data.
| Name | 259 ransomware / [259461356@qq.com].259 virus |
|---|---|
| Type | Ransomware, data locking malware, cryptovirus |
| Malware family | Dharma |
| Encryption method | AES, although other algorithms can be used as well |
| File extension | .259, although other strings, such as user ID, are added to each of the files, for example: picture.jpg.id-V724R243.[259461356@qq.com].259 |
| Ransom note | Pop-up window titled “259461356@qq.com” and a text file “FILES ENCRYPTED.txt” |
| Contact | 259461356@qq.com |
| File Recovery | If no backups are available, recovering data is almost impossible. Nonetheless, we suggest you try the alternative methods that could help you in some cases – we list them below |
| Malware removal | Perform a full system scan with powerful security software, such as SpyHunterCombo Cleaner |
| System fix | Ransomware might damage some Windows system files and configuration settings in a way that would prevent the OS from operating the way it used to. In case you experience crashes, BSODs, errors, and other stability issues, scan your machine with FortectIntego |
Since Dharma is a large malware family, there are several ways how the payload may be delivered to victims. Nonetheless, researchers discovered that most infections occur when users attempt to open malicious spam email attachments, which are obfuscated by double extension. In other words, users might believe that they are opening a PDF file, while in reality, they are opening an executable (EXE) file.
259 files virus then modifies Windows system files to perform a successful encryption process of files with predetermined extensions, such as DOC, ZIP, JPG, TXT, XLS, and many others. Unfortunately, this process is rather quick, and it is performed much quicker than one can notice that something is wrong and interrupt the procedure by shutting down the PC.
As soon as 259 ransomware finishes the data-locking process, it delivers two ransom notes to ensure that victims know what happened to their data. Unlike stealthy malware that operates in the background and does everything to remain invisible, ransomware almost always provides some type of note for users to contact the attackers. As usual, hackers leave an email (259461356@qq.com) and other details in the note.

FILES ENCRYPTED.txt is a brief message that only notifies about the contact email, while the popup window includes much more details about what victims have to do:
All your files have been encrypted!
All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail 259461356@qq.com
Write this ID in the title of your message V724R243
In case of no answer in 24 hours write us to theese e-mails:259461356@qq.com
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.Free decryption as guarantee
Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
Besides encrypting data, the virus also changes the way Windows operates. For example, it attempts to delete System Restore points, as well as Shadow Copies, to prevent people from using automatic system recovery options. Also, it can change Windows registry keys for persistence. Thus, you should scan your device with FortectIntego after you remove 259 ransomware to automatically repair some of the system files that could have been damaged during the attack.
Speaking of 259 ransomware removal, you should use powerful anti-malware, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, to eliminate all the malware-delivered files and ensure that no incoming files are encrypted in the future.
.259 files can only be recovered safely via backups
As explained by cybercriminals in the ransom note, users need to pay Bitcoin in order to recover .259 virus files. They also warn victims that modifying the file extension or employing third-party security solutions can permanently damage the locked data. While malicious actors could be bluffing, they might also be correct.

Many users mistakenly believe that they can remove .259 extension as soon as they scan their systems with anti-malware. However, it is not the case, and files will remain locked (although ransomware removal is a necessary process for recovery from the infection).
The truth is, if malware was operating correctly during the infection and encryption process, the only secure way to restore locked files is by using backups, as only cybercriminals have a unique key that is required to decrypt data. However, there are several risks involved when it comes to ransom payments to attackers, as they might simply fail to deliver the decryptor in the first place.
Thus, experts[2] do not recommend paying ransoms and instead employ alternative .259 file recovery solutions below. They include using automated Windows recovery options or employing third-party tools.
259 ransomware removal instructions
Many users get extremely anxious after being hit by ransomware, while others know nothing about this type of infection. As a result, many believe that 259 ransomware removal will also restore the encrypted files. However, as explained above, it is not the case at all. The easiest way to restore data is by using backups that are located on a different medium, such as an external hard drive or a Cloud.

If you have no backups, you should first make a copy of your most important files before you remove 259 ransomware from your computer. Otherwise, you might damage the files permanently. Besides, cybersecurity researchers might be able to find bugs within this version of Dharma and release a free decryption tool in the future.
To delete 259 virus from your system, you should employ powerful security applications that can detect the malicious payload.[3] We recommend using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes – these security tools should also prevent you from being infected in the future.
Was this guide helpful?
Be the first to comment