Dever ransomware is a computer threat that belongs to one of the most prominent file locking malware families

Dever ransomware is malware that locks all pictures, music, videos, documents, databases, as well as other non-system and non-executable files on the system and holds them hostage until a ransom is paid in Bitcoin. The virus is a variant of Phobos ransomware, and hackers behind it specialize in attacking various businesses and organizations, although regular users may also be affected. Unfortunately, no Dever ransomware decryptor currently exists, so there are very few options when it comes to data recovery without paying a ransom to criminals.
Dever ransomware uses the AES encryption algorithm to lock files and applies .Dever extension to each of them. However, this is not the only symptom of the infection, as victims can also see a pop-up window titled “encrypted” (a .hta file), as well as a text file “info.txt” in almost every folder of the computer. As it is typical with Phobos variants, the ransom amount is not provided, and instead, users are asked to contact crooks via bexonvelia@aol.com, lizethroyal@aol.com or maitlandtiffaney@aol.com emails.
| Name | Dever ransomware |
| Type | File locking virus, cryptomalwawre |
| Family | The virus belongs to Phobos ransomware family |
| Primary targets | Dever primary targets are public entities and businesses |
| Attack vector | Most malware victims were infected via inadequately protected Remote Desktop connection, although there are several other distribution techniques that hackers could use, including malicious spam/targeted emails, exploits, fake updates, etc. |
| Extension | Once the infection routine is triggered, all personal files are appended with .id[XXXXXXXX-XXXX].[bexonvelia@aol.com].Dever extension (the email address in the extension might vary) |
| Ransom note | Two ransom notes are provided: info.hta (short version) and the pop-up window titled “encrypted” |
| Contact | Users are prompted to contact cybercriminals via bexonvelia@aol.com, lizethroyal@aol.com or maitlandtiffaney@aol.com emails |
| Related | AntiRecuvaAndDB.vir.exe |
| Detection |
Multiple engines detect the sample as follows:
|
| File decryption | No decryptor is currently available, although victims can retrieve data from backups or trying the third-party recovery tools |
| Malware removal | Use reputable anti-malware software to perform a full system scan in Safe Mode with Networking as explained in our instructions below |
| System recovery | If you experience system instability after the infection, you should use PC repair software FortectIntego to fix virus damage |
Dever ransomware can be spread in multiple different ways, although security researchers noticed that most Phobos variants are delivered via incorrectly protected RDP connections.[1] Other methods may include:
- Spam email
- Exploits[2]
- Fake updates
- Web injects
- Software cracks, etc.
Soon after the infiltration, the Dever virus attempts to configure Windows for a smooth infection and file encryption process. For example, most ransomware viruses are known to delete Shadow Volume Copies in order to prevent easy data recovery, alter Windows registry for persistence, and even terminate security measures like a firewall or anti-malware software to prevent Dever ransomware removal.
After the necessary changes are made, Dever ransomware encrypts all the data with a symmetric encryption algorithm[3] AES – a secret key is used to lock and unlock all the data on the machine and the connected network, and it is sent off to a Command & Control server which is only accessible to hackers.
To retrieve the required key, victims are asked to pay a ransom in Bitcoin in an info.txt file which reads:
!!!All of your files are encrypted!!!
To decrypt them send e-mail to this address: bexonvelia@aol.com.
If we don’t answer in 24h., send e-mail to this address: maitlandtiffaney@aol.com
In the Info.hta note, hackers behind Dever ransomware explain what happened to users' files and explain everything in more detail. They also offer a free test decryption service, which is meant to increase the sense of credibility when it comes to file decryption – criminals want to prove that Dever ransomware decryptor exists and they can get it as soon as they pay the money.

Security advocates[4] advise users to stay away from criminals, as they might never send the required decryptor after the payment, although some users might not have another choice. If you choose to pay, be aware that you might lose your money along with your files. If you had no backups, you could try using third-party recovery software.
Note that you need to remove Dever ransomware before you attempt to recover your data, as malicious background processes keep running to encrypt newly added files. Thus, make a copy of encrypted data and terminate the virus with anti-malware software. If the virus affected your Windows OS, you can use FortectIntego to fix virus damage.
Stop manual malware attacks by correctly protecting your Remote Desktop connections
As previously mentioned, mostly RDP attacks are used by Phobos actors to infect victims with ransomware. Therefore, the key to avoiding the infections is protecting Remote Desktop connections as much as possible. Unfortunately, there are thousands of companies and businesses that still use RDPs that are publicly exposed, and do not apply the Network Level Authentication when connecting.[5] Due to this, RDP attacks became one of the primary ransomware and other malware distribution methods, as they are extremely effective, and can also allow the attacker to act “on the spot.”
Therefore, make sure you protect your business from ransomware by enabling Network Level Authentication (NLA) via System Properties, limiting the access to only those that need it, never using the default TCP and UDP port 3389, and protecting the RDP by using a strong password created from alphanumeric characters.
Additionally, you should also make sure that all the other basic protection measures are applied, including regular backups, staff training, application of software updates, comprehensive security software, etc.

Backup the encrypted data before you remove Dever ransomware
If is very important to note that Dever ransomware removal might permanently damage and corrupt your files – even the malicious actors then would not be able to return your data. Therefore, before you do anything, you should copy all the encrypted files (unless you have working backups – you should then simply get rid of the Dever virus as explained below) to a flash drive or virtual storage.
Once that is complete, you need to remove Dever ransomware from your machine as soon as possible by using anti-malware software. Note that this virus keeps running in the background, so it will encrypt all the incoming files, as well as recovered backups if it is not terminated. If you had no backups, you could attempt to recover your files with the help of third-party recovery tools, although the chances of this method being successful are slim. Alternatively, you can wait till security researchers find bugs within malware's code and create a free Dever ransomware decryptor.
Did this guide help?
Be the first to comment