ArmaLocky impersonates notorious Locky

ArmaLocky virus functions as crypto-malware which imitates the infamous Locky ransomware which now terrifies users with its latest version of Lukitus.
However, despite how convincing this variation may seem due to its ransom note, in fact, it is just an imitator[1] spreading under the trojan name of Troj.Ransom.W32.Agent!c, Trojan[Ransom]/Win32.Agent, Win32.Trojan-Ransom.ArmaLocky.A, Ransom.Agent!8.6B7 (cloud:ND3t9VYK6xK), etc. Unfortunately, it encrypts files and appends .armadilo1 file extension.
The ransom note resembles the one presented by Locky as it informs victims that RSA-4096 and AES-256 encryption was used to encode the files. Victims should download the Tor browser and access a specific site to pay the ransom in bitcoins. The malware also exhibits a tendecy to connect to the web via Internet Explorer.
No further specifications about the size of the ransom are presented. Since the malware is still under development, it is not recommended to remit the payment. Instead, focus on ArmaLocky removal. FortectIntego or MalwarebytesMalwarebytes will accelerate the elimination process.
Locky inspires other cyber criminals to continue the cyber terror
Unfortunately, the original version of this threat does not intend to withdraw from the market any time soon. Such scenario would be irrational since it has brought millions of dollars to the owners. For instance, one of the targets, — hospital – paid 40 bitcoins ransom amounting to $17 000.[2]
Therefore, gullible users believing that they are dealing with the original threat, which is still undecryptable, might risk paying the ransom. Speaking of ArmaLocky ransomware, there is no certainty that the perpetrators will send the data back. Ransomware became a profitable business but only few cyber criminals play fair. Thus, remove ArmaLocky right away.
Crypto-malware transmission ways
Following the manner of Locky spreading tendency, this sample of ransomware is likely to be distributed via spam emails. Interestingly, the ransom note also includes a .zip folder password. Thus, beware of the emails with questionable invoice files.
IKARUSdilapidated campaign [3], which delivered Diablo6 and Lukitus version, has the capability to infect a company network and send the emails with fake scanned files attachments. Thus, you should be wary of this method. Thus, double check before opening any files.
In addition, ArmaLocky hijack might occur if you download questionable applications from secondary sources. Lastly, do not click on any account verifications and install updates which are promoted by random websites. If you received an email to verify your website account again, check for full credentials of the company.
Get rid of ArmaLocky malware
You can delete the virus with the assistance of malware elimination tool. It is not surprising if you cannot remove ArmaLocky virus from the attempt. The virus is likely to meddle with certain system functions. In case, you encounter ArmaLocky removal problems, reboot the system in Safe Mode. You will find further guidelines below.
Note that the malware targets all users without exception. Thus, if you live in Portugal[4] or Sweden, beware of the threat.
Did this guide help?
Be the first to comment