Moloch ransomware – new cryptovirus from the Makop ransomware family

Moloch ransomware is a computer virus infection that encrypts all personal victim files on an affected device and demands a ransom for unlocking them. This file-locking parasite belongs to a relatively small Makop ransomware family compared to others, such as Djvu or Dharma.
This cyber infection renames all commonly used files by appending original filenames with unique victim IDs, criminal contact details in brackets [moloch_helpdesk@tutanota.com], and .moloch extension. After the files are renamed and encrypted, they are rendered useless until a decryption tool is employed.
Completing the first part of its purpose, the Moloch virus creates ransom notes, named readme-warning.txt, and spreads them throughout the infected computer so the victims would find them wherever they look. Their purpose is to intimidate and convince the victims of this cyber attack to agree with the ransom demands.
| name | Moloch ransomware |
|---|---|
| type | File-locking virus, crypto-malware |
| family | Makop |
| Ransom note | readme-warning.txt |
| appended file extension | Personal files are renamed by adding appointed user ID, [moloch_helpdesk@tutanota.com], and .moloch extension to the original filenames |
| criminal contact details | Assailants provide two emails to establish contact with them -moloch_helpdesk@tutanota.com and moloch_helpdesk@protonmail.ch |
| Virus removal | Cyber infections should be dealt with immediately with the help of professional, reliable anti-malware tools |
| System health | Since cryptoviruses make modifications to system files and settings, it's of utmost importance to use system repair tools like the FortectIntego to restore default values |
Ransomware is created to extort various cryptocurrencies, and Moloch virus isn't an exception. Cybercriminals in the ransom note state that the decryption tool's payment will have to be made in Bitcoins (BTC). However, the amount isn't specified.
Like almost all ransomware developers, the creators of this malware offer free decryption of one file, trying to prove that they really have the necessary decryption tool and they would share it with the victims after the payment is forwarded. Here's the whole message from the readme-warning.txt:
::: Greetings :::
Little FAQ:
.1.
Q: Whats Happen?
A: Your files have been encrypted and now have the “moloch” extension. The file structure was not damaged, we did everything possible so that this could not happen.
.2.
Q: How to recover files?
A: If you wish to decrypt your files you will need to pay in bitcoins.
.3.
Q: What about guarantees?
A: Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities – nobody will cooperate with us. Its not in our interests.
To check the ability of returning files, you can send to us any 2 files with SIMPLE extensions(jpg,xls,doc, etc… not databases!) and low sizes(max 1 mb), we will decrypt them and send back to you. That is our guarantee.
.4.
Q: How to contact with you?
A: You can write us to our mailbox: moloch_helpdesk@tutanota.com or moloch_helpdesk@protonmail.ch
.5.
Q: How will the decryption process proceed after payment?
A: After payment we will send to you our scanner-decoder program and detailed instructions for use. With this program you will be able to decrypt all your encrypted files.
.6.
Q: If I don’t want to pay bad people like you?
A: If you will not cooperate with our service – for us, its does not matter. But you will lose your time and data, cause only we have the private key. In practice – time is much more valuable than money.
:::BEWARE:::
DON'T try to change encrypted files by yourself!
If you will try to use any third party software for restoring your data or antivirus solutions – please make a backup for all encrypted files!
Any changes in encrypted files may entail damage of the private key and, as result, the loss all data.
Cybercriminals are constantly creating new ransomware variants from certain families. Makop virus authros released multitude of versions so far, and they are not about to stop any time soon. Although it's considered as a small family, it still has more than a few variations:

All in all, all malware should be eliminated from affected computers immediately. To remove Moloch ransomware with a push of a button, we recommend using trustworthy anti-malware software such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes or any similarly powerful tools.
Although manual Moloch ransomware removal is possible, it's recommended only for highly experienced computer users, so it's better to leave it to professionals. When you get rid of the cyber infection, the next step should be to take care of the device's overall health since cryptoviruses often cause damage to system files and settings without encrypting them. Experts[1] suggest using the powerful system repair toolkit of the FortectIntego app.
Instructions to increase home cybersecurity level to avoid cyberattacks
In 2020, companies and everyday computer users were hit by ransomware on a daily basis. Research suggests[2] that in 2021 ransomware damage costs will reach $20 billion. So there wasn't a better time to improve your cybersecurity level. Stick with our guidelines below, and you might avoid becoming the next victim of cybercriminals.
- Purchase a dependable anti-malware tool. Update its database regularly to stop the latest malware creations.
- Maintain your system performance and health with powerful system tune-up/repair software.
- Install the latest updates of all software, most of all your operating system.
- Keep backups of all essential data, preferably on two separate devices, e.g., USB drive, cloud, external storage, etc.
- Learn the basic malware delivery techniques used by cybercriminals by reading our articles or other cybersecurity newsletters.
Simple steps for Moloch ransomware removal
Victims should never trust cyber criminals. There are numerous cases where after paying the requested ransom, cybercriminals either disappeared, asked for more money, sent a non-operational decryption tool, and so on. That being said, we highly advise our readers to remove Moloch ransomware immediately.

The best way to do it is by using professional anti-malware software, like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes that will not only eliminate the cyber infection with all its components but protect your computer systems from future incidents. When you get rid of the cryptovirus, the next thing is taking care of your device's systems wellbeing.
There are various kinds of malware,[3] but all of it tends to corrupt system files and settings, that why we recommend performing a system tune-up right after Moloch ransomware removal. The most efficient way to do that is to use system repair tools such as the FortectIntego app.
Was this guide helpful?
Be the first to comment