Leakthemall ransomware in a newly discovered virus that will change your file names to .crypt, .montana or .beijing

LeakTheMall ransomware (aka LeakThemAll) is a data locking virus that was first discovered by cybersecurity researcher Amigo-A.[1] If your computer gets infected by this malware, your data will be encrypted with a “.crypt,” “.montana,” or “.beijing” extensions. For example, “a.pdf” would become “a.pdf.crypt,” b.pdf” as “b.pdf.crypt,” and exactly the same renaming applies to the Montana virus and Beijing virus, which will apply .montana and .beijing extensions accordingly.
When the encryption[2] is complete, ransom note files appear in the affected folders. The .crypt virus will give you a ReadMe.txt file with further instructions to decrypt your data. Beijing virus will show up !Recover.txt file and Montana virus will display !Help!.txt. Inside, the developers of Leakthemall ransomware are asking for a ransom and provide further instructions on how to proceed to unlock your files.
| NAME | LeakTheMall ransomware, LeakThemAll virus, Beijing virus, Montana virus |
|---|---|
| File extension | .crypt , .montana , .beijing |
| Ransom file name | ReadMe.txt , !Help!.txt , !Recover.txt |
| Distribution | Spam email and its malicious attachments, spoof downloads, botnets, trojans, fake updates, repackaged and infected installers |
| Contact email | leakthemall@protonmail.com, montanarecover@mail.ee or montanarecover@cock.li, beijing520@aol.com, beijing520@cock.li |
| Damage | Encrypted computer data without the ability to use it without paying a ransom or encrypting the files |
| Issues | Victims cannot open files. Computer data is encrypted and an extension (.crypt / .beijing / .montana) is added to all files. Ransom file (ReadMe.txt , !Help!.txt or !Recover.txt) appears on the desktop. |
| Recommend removal | To find and remove possible ransomware infection please use anti-malware like SpyHunterCombo Cleaner |
| System repair | Computer infections might result in serious damage to your system files and interrupt the usual way your PC works. We recommend using a trusted PC repair tool line FortectIntego to get your PC working normally again. |
The fraudsters will ask you to contact them via email leakthemall@protonmail.com for the crypt virus, montanarecover@mail.ee, or montanarecover@cock.li for the Montana virus, and beijing520@aol.com or beijing520@cock.li for the Beijing virus decryption.
If you proceed with the instructions, they might unlock a couple of files just to show the victim that decryption is possible. While encryption of your files is in progress, some of your data might have been stolen, and if you refuse to cooperate with cybercriminals, they will threaten to publicize the content of the stolen data.
However, LeakTheMall ransomware removal should be performed regardless if you agree to pay or not. We recommend using powerful anti-malware, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, for the purpose. Later, you can employ FortectIntego to fix potential damage caused to Windows system files for full OS recovery.

Do not pay the ransom to unlock .crypt, .montana or .beijing files – look for alternatives instead
Malware developers warn victims that any modifications done to the files (copying, renaming, etc.), any tries of decryption with third-party software, or a computer shutdown/restart might cause them to be non-decryptable. Hence, your data could be permanently lost, unless the malware itself isn't completed and has serious flaws,[3] decryption without the key from the ransomware developers isn't possible.
Despite that, it is strongly recommended not to comply with the ransom demands because even if the money is paid, users might still not receive the decryption key. Your data would still be encrypted, but your wallet would be a bit lighter. The ransomware has to be deleted from the system to prevent its further encryption. Unfortunately, this won't decrypt your files. The only way to recover your data is if you've made a backup on a separate location prior to the contamination.
Below is the message of the LeakTheMall ransomware with .crypt file extension ransom note ReadMe.txt reads:
Hello
IF YOU ARE READING THIS, IT MEANS YOUR DATA IS ENCRYPTED AND YOUR PRIVATE SENSIVITIVE INFORMATION WAS STOLEN!
READ CAREFULLY THE WHOLE INSTRUCTIONS TO AVOID PROBLEMS WITH YOUR DATAYOU HAVE TO CONTACT US IMMEDIATELY TO RESOLVE THIS ISSUE AND MAKE A DEAL!
!!!WARNING!!!
DO NOT Modify, Rename, Copy or Move any file. You can DAMAGE them and decryption will be impossible!
DO NOT Use any third-party or public decryption software, it also may DAMAGE files.
DO NOT SHUTDOWN or RESET your system, it can damage files.There is ONLY ONE possible way to get back your files
Do not waste your time, contact us and pay for special DECRYPTION KEY. The key is all you need.
For your guarantee we will decrypt 2 of your files for free, as a proof that it works.Your network was fully COMPROMISED! We Can discuss how to secure it as a bonus.
The data that we gathered could be published in MASS MEDIA for BREAKING NEWS!
If we make a deal everything would be kept in secret and all your data will be restored.
I could make them public them if you decide not to pay.contact us immediately:
leakthemall@protonmail.com
The LeakTheMall ransomware with .beijing file extension will show the following ransom note !RECOVER.txt:
ALL YOUR DATA WAS ENCRYPTED
Whats Happen?
Your files are encrypted, and currently unavailable. You can check it: all files on you computer has extension .beijing
By the way, everything is possible to restore, but you need to follow our instructions. Otherwise, you cant return your data (NEVER).
What guarantees?
It's just a business. We absolutely do not care about you and your deals, except getting benefits.
If we do not do our work and liabilities – nobody will not cooperate with us.
It's not in our interests.
If you will not cooperate with our service – for us, its does not matter. But you will lose your time and data, cause just we have the private key.
In practise – time is much more valuable than money.
What should You include in your message?
1. Your country and city
2. This TXT file
3. Some files for free decryption
Free decryption as guarantee!
Before paying you send us up to 2 files for free decryption.
Send pictures, text files. (files no more than 1mb)
If you upload the database, your price will be doubled
Contacts:
beijing520@aol.com
beijing520@cock.liYour Personal ID: –

LeakThemAll ransomware with .montana file mark will give the !HELP!.txt ransom note:
Hello.
If you are reading this, it means your data is encrypted and your private sensivitive information was stolen!
Read carefully the whole instructions to avoid problems with your data.
You have to contact us immediately to resolve this issue and make a deal!!!!WARNING!!!
DO NOT modify, rename, copy or move any file. You can DAMAGE them and decryption will be impossible!
DO NOT use any third-party or public decryption software, it also may DAMAGE files.There is ONLY ONE possible way to get back your files.
Do not waste your time, contact us and pay for special DECRYPTION TOOL. The tool is all you need.
For your guarantee we can decrypt 2 of your text or image files for free, as a proof that it works.Your network was fully COMPROMISED! We can discuss how to secure it as a bonus.
The data that we gathered could be published in MASS MEDIA for BREAKING NEWS!
If we make a deal everything would be kept in secret and all your data will be restored.
I could make them public them if you decide not to pay.
Contact us immediately:
montanarecover@mail.ee
montanarecover@cock.li
There are many other ransomware viruses such as Clay, Conti, or the notorious new Stop/Djvu ransomware version – Mmpa virus. These programs operate the same way – encryption and ransom demand. They differ in just two aspects – the cryptographic algorithm used and the amount of money asked for the decryption code as a ransom. To avoid dealing with this kind of cybercriminals, it is very important to keep backups in different locations, such as removable storage devices, remote servers, etc.
Ways to decrypt your files and prevent future ransomware attacks
There are numerous ways for your system to get infected by ransomware or some other type of malware. It is usually acquired via spam mail, “cracking” tools, trojans, etc. Scam mail usually contains download links of malicious software, or the infection files could just be added to the email as attachments. There are various ways of what these files might look like (i.e., .exe files, JavaScript, MS Office, .pdf, etc.), and the minute they're opened, the infection on the user begins.
Trojans are other threats that cybercriminals might distribute in such a way- it is malicious software that can enable cyber-criminals to steal your sensitive data, gain backdoor access to your system, download additional malware, etc. “Cracking” tools are used to illegally activate licensed software, but instead of doing that, it might install some malware.

Users should never open irrelevant, fishy looking emails. And especially never open any attachments received in emails from suspicious, unknown senders. All downloads and software updates should be done only via trustworthy sources. Usage of “cracking” tools is not recommended as it could lead to a system infection. Computer users should obtain legitimate antivirus software, keep it up-to-date, and regularly scan their computer systems. Keep backups of data in different locations. If your system is infected with the ransomware, we recommend using them!
Keep in mind that you have to remove LeakTheMall ransomware with an anti-malware tool (such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes) before you attempt to use backups or other data recovery solutions. Otherwise, all your files will be encrypted repeatedly.
After LeakTheMall ransomware removal, you can then employ alternative data recovery methods we list below. Keep in mind that they are likely not to work, but since there is a chance that malware failed to perform its certain functions, you might be able to restore all your data for free. In other words, you will never know before you try. Note that it is advised to copy the encrypted files to another medium before doing so.
Did this guide help?
Be the first to comment