Bulwark ransomware is a MedusaLocker variant that can be devastating to those affected

Bulwark is a ransomware-type virus that first emerged in mid-October 2022. It encrypts all personal files on the target machine and holds them hostage so that victims would have to pay them money in exchange for a decryption tool that is meant to restore the data. All personal files are affected, including pictures, documents, and databases, all of which receive the .bulwark7 extension. Just like it's common to MedusaLocker variants, data is encrypted with a combination of AES and RSA encryption algorithms, making a recovery without the key difficult, if not impossible.
After the Bulwark virus encrypts files, it delivers a ransom note !-Recovery_Instructions-!.html, which is opened via the browser window. According to the message, hackers claim that they have hacked the whole network, and victims have only 72 hours for negotiation – they need to write an email to ithelp09@wholeness.business or ithelp09@decorous.cyou to begin talks about the payment. Experts recommend avoiding this and seeking alternative solutions for remediation.
| Name | Bulwark |
|---|---|
| Type | Ransomware, file-locking malware, cryptovirus |
| File extension | .bulwark7 |
| Ransom note | !-Recovery_Instructions-!.html |
| Encryption | AES + RSA |
| Data Recovery | If no backups are available, recovering data is almost impossible. However, we suggest you try the alternative methods that could help you in some cases – we list them below |
| Malware removal | Manual virus removal is not recommended, as it might be difficult for regular users. Instead, SpyHunterCombo Cleaner or other anti-malware tools should be used |
| System fix | Malware can seriously impact a Windows computer's performance and stability after it is removed. We recommend scanning the system with FortectIntego to remedy it and avoid significant stability issues |
The data-stealing trick
Some ransomware strains focus on home users (for example, Djvu versions Powz and Adlg) – these attacks are usually high in volume, and more smaller ransoms can be acquired this way. In the case of Bulwark ransomware, its attacks are focused mainly on businesses and organizations. Corporate entities are then demanded large sums of money that most regular people would never be able to pay.
All the details about the attack can be found on a rather extensive ransom note, delivered in an HTML format. The full message reads as follows:
If you get this message, your network was hacked!
After we gained full access to your servers, we first downloaded a large amount of sensitive data and then encrypted all the data stored on them.That includes personal information on your clients, partners, your personnel, accounting documents, and other crucial files that are necessary for your company to work normally.
We used modern complicated algorithms, so you or any recovery service will not be able to decrypt files without our help, wasting time on these attempts instead of negotiations can be fatal for your company.
Make sure to act within 72 hours or the negotiations will be considered failed!
Inform your superior management about what's going on.
Contact us for price and get decryption software.
Contact us by email:
ithelp09@wholeness.business
If you will get no answer within 24 hours contact us by our alternate emails:
ithelp09@decorous.cyou
To verify the possibility of the recovery of your files we can decrypted 1-3 file for free.
Attach file to the letter (no more than 5Mb).
If you and us succeed the negotiations we will grant you:
complete confidentiality, we will keep in secret any information regarding to attack, your company will act as if nothing had happened.
comprehensive information about vulnerabilities of your network and security report.
software and instructions to decrypt all the data that was encrypted.
all sensitive downloaded data will be permanently deleted from our cloud storage and we will provide an erasure log.
Our options if you act like nothing's happening, refuse to make a deal or fail the negotiations:
inform the media and independent journalists about what happened to your servers. To prove it we'll publish a chunk of private data that you should have ciphered if you care about potential breaches. Moreover, your company will inevitably take decent reputational loss which is hard to assess precisely.
inform your clients, employees, partners by phone, e-mail, sms and social networks that you haven't prevent their data leakage. You will violate laws about private data protection.
start DDOS attack on you website and infrastructures.
personal data stored will be put on sale on the Darknet to find anyone interested to buy useful information regarding your company. It could be data mining agencies or your market competitors.
publish all the discovered vulnerabilities found in your network, so anyone will do anything with it.
Why pay us?
We care about our reputation. You are welcome to google our cases up and be sure that we don't have a single case of failure to provide what we promissed.Turning this issue to a bug bounty will save your private information, reputation and will allow you to use the security report and avoid this kind of situations in future.
Your personal ID
Ransomware authors continue to find new methods to extort money from victims. Attacks against corporate networks did not prove as successful before, as companies usually have reliable backup systems installed. As a result, there's no need for the ransom developers to get paid – all the data is simply restored from backups.

Cybercriminals then came up with an idea to steal sensitive corporate information during the attack, which can be used to blackmail victims. As seen in this ransom note, there are plenty of threats about disclosing the information to third parties and underground cybercrime communities, as well as employing DDoS attacks[1] against the company.
Despite this, paying the attackers can be extremely risky. There is no guarantee that they won't publish the data regardless of whether the ransom payment was made or not. Therefore, we recommend avoiding all communication with the attackers and using alternative solutions instead – the recovery begins with Bulwark ransomware removal.
Tackling the infection
During the infection phase, ransomware frequently establishes an internet connection with a remote Command & Control[2] server. This gives the attackers the ability to carry out a number of malicious activities, such as updating their malware or sending additional commands. In order to prevent reinfection, the network connection should also be blocked off. Before beginning the ransomware removal process, disconnect your computer from the network as follows:
- Type in Control Panel in Windows search and press Enter
- Go to Network and Internet

- Click Network and Sharing Center

- On the left, pick Change adapter settings

- Right-click on your connection (for example, Ethernet), and select Disable

- Confirm with Yes.
While some ransomware does have a tendency to self-destruct after encrypting data, this isn't always the case. For instance, it frequently spreads alongside other malware, such as data stealers or keyloggers.[3] Therefore, getting rid of all malware components at once is crucial. The simplest approach is using powerful anti-malware software, like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes – it can locate all the malicious components, quarantine them, and then remove them securely.
In some cases, security software's operation may be hindered by malware, which may result in incomplete removal or other issues. In such a case, you can access Safe Mode and perform Bulwark virus removal from there:
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing the F8 button (if that does not work, try F2, F12, Del, etc. – it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.

Windows 10 / Windows 8
- Right-click on the Start button and select Settings.
- Scroll down to pick Update & Security.
- On the left side of the window, pick Recovery.
- Now scroll down to find the Advanced Startup section.
- Click Restart now.

- Select Troubleshoot.

- Go to Advanced options.

- Select Startup Settings.

- Click Restart.
- Press 5 or click 5) Enable Safe Mode with Networking.
Fixing damaged system files
Malware can cause tremendous damage to Windows systems to the point where a full reinstallation could be required. For example, an infection can alter the Windows registry database, damage vital bootup, and other sections, delete or corrupt DLL files, etc. Antivirus software can't repair damaged files, and a specialized app should be used instead.
- Download FortectIntego
- Click on the ReimageRepair.exe

- If User Account Control (UAC) shows up, select Yes
- Press Install and wait till the program finishes the installation process

- The analysis of your machine will begin immediately

- Once complete, check the results – they will be listed in the Summary
- You can now click on each of the issues and fix them manually
- If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.

Data recovery explained
Although the FBI and security experts generally discourage paying ransoms or even contacting cybercriminals, the victim's choice is always final. But keep in mind that by paying the ransom, you're only encouraging the attackers to create more malware and infect other people because it shows the profitable nature of the illicit business. Maintaining safe data backups, which can be done using reliable services like Google Drive or OneDrive, is the only way to prevent the devastation caused by a ransomware attack. We give recommendations for this below.
As evident, the safest way to restore encrypted files is by using backups. If you don't have working backups or they were encrypted as well, you could try using third-party recovery software or waiting for a decryptor to be developed by security researchers, which may or may not happen.
Did this guide help?
Be the first to comment