MongoLock ransomware is a cryptovirus that can delete all files and format backups

MongoLock ransomware is a file locking virus that was first spotted performing attacks in September 2018. Cybercriminals mostly targeted vulnerable MongoDB databases, deleted them, made a copy accessible only to hackers, and then dropped a ransom note Warning.txt which contains all the details about the attack. The developers of MongoLock ransomware ask for 0.1 or 0.6 Bitcoin and also urge users to contact them via the unlockandrecover@pm.me, dbbackups@protonmail.com or mongodb@8chan.co. Crooks also warn that the payment must be performed within 24 hours, or the data will be deleted permanently. Trend Micro researchers recently discovered a new variant of malware – it instantly erases databases and keeps scanning the device for further deletion.[1] While MongoLock ransomware name is relatively new, first attacks were performed back in 2017, when malware encrypted more than 26 000 servers.[2] Currently, criminals already earned more than $11,000 based on the provided Bitcoin address.[3]
| Name | MongoLock ransomware |
|---|---|
| Type | Cryptovirus |
| Ransom note | Warning.txt |
| Contact email | unlockandrecover@pm.me |
| Ransom amount | 0.1 BTC or 0.6 BTC |
| Affects | Files and databases |
| Distribution | Malicious payload dropper distributed on the internet |
| Removal | Use anti-malware for MongoLock ransomware elimination and clean the system with FortectIntego |
The most recent variants of MongoLock ransomware are hosted on PythonAnywhere online hosting service. Once trying to access hxxp://update.pythonanywhere.com/d, a malicious update.exe is downloaded. Additionally, hxxp://update.pythonanywhere.com redirects all users to a spoofed Chinese gaming site.
MongoLock ransomware virus can wipe the whole MongoDB database after the ransom is asked form the victim. However, the decryption and file recovery is only alleged and cannot be guaranteed. Even when you pay demanded 0.1 Bitcoin, there is little to no possibility that you can get your files back.
Developers behind the MongoLock ransomware ensure the persistence of the malware with additional system changes like altering registry entries to make the ransomware launch its malicious payload every time your device is restarted. Also, this ransomware may add files or programs on the system to disable certain features or functions of antivirus and other security programs.
the older versions of MongoLock ransomware may start the encryption process.[4] Every file or database gets encrypted when the original code is changed. Encoded audio, video files, documents, photos or databases, archives get unreachable. However, new versions of MongoLock that were discovered in late 2018 will delete all the data in drives A and D and copy it to a remote server instead.
MongoLock ransomware then delivers ransom message that contains a brief note to the victim and reads the following:
Warning!
Your File and DataBase is downloaded and backed up on our secured servers. To recover your lost data : Send 0.1 BTC to our BitCoin Address and Contact us by eMail with your server IP Address and a Proof of Payment. Any eMail without your server IP Address and a Proof of Payment together will be ignored. We will drop the backup after 24 hours. You are welcome!
Mail:unlockandrecover@pm.me
BitCoin:1NrZsNppQqXNiYnu34MPo6K2sHYyMPjR4h
Even though MongoLock ransomware demands for a payment, you shouldn't pay them because it leads to permanent data and money loss.[5] The official decryption tool is not developed yet, so you need to employ data backups and software designed to restore encrypted or deleted files.
You should focus more on MongoLock ransomware removal and then worry about data recovery. The best file restoring method is backups on external devices or cloud services. However, when people are not having these, they can employ software developed for the recovery specifically.
When you remove MongoLock ransomware from the device completely, you can freely use your preferred method for file restoring. Nevertheless, you need to clean the system thoroughly. Choose a reputable anti-malware for the initial ransomware elimination and then use FortectIntego and clean the virus damage. We have a few additional software suggestions below the article.

Clicking on the link in the email may trigger malicious payload installation
The most used malware spreading technique for many years is a spam email. These campaigns use different tactics for each type of malware and distribute dangerous products on the targeted devices with one click on the hyperlink or email notification.
A payload dropper that installs malicious ransomware installation, in most cases, come from email attachments or the email itself because sale-looking notifications often contain malicious links or document attachments with malicious macros.
Experts advise paying more attention to the emails you get and open because opening one MS document or clicking on the displayed link may trigger the script that loads malware on the device. You can avoid these infiltrations if you avoid opening unexpected emails with file attachments.
Terminate MongoLock ransomware and additional programs or processes to lower the risk
For the best results of MongoLock ransomware removal, you should choose professional anti-malware tools and scan the device thoroughly. If you have an antivirus already on your system, try rebooting your computer in the Safe Mode and scan the machine then. It ensures that your tool works appropriately and a virus is not affecting the vital functions.
If you need additional suggestions for tools that can remove MongoLock ransomware and other malware or virus damage, employ FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes for the process. We can recommend these tools as feel free to use one or a few of them to double-check that the system is clear.
When you get rid of MongoLock ransomware virus, you can try data recovery methods. It is important to keep your backups on external devices or cloud services, but you may be caught off guard with cryptovirus. If have no file backups tri your data recovery methods below the article.
Did this guide help?
Be the first to comment