N1n1n1 ransomware is a crypto virus that targets users' personal files

N1n1n1 ransomware is a file locking virus that first emerged in late 2016. The virus is propagated in usual methods, such as phishing[1] emails, malicious websites and through the unprotected RDP configuration, and uses the combination of AES an RSA encryption algorithms[2] to lock up data. The initial version of the virus modified file names as follows: [original_file_name][8-9 ransom characters][original_file_extension] and dropped ransom note “how return files.txt” that asked 1.5 BTC for file release. Since then, several variants emerged, but very few changes were added by cybercriminals. The newest version, which showed up in August 2018, adds .jpa prefix, asks victims to contact them via z44@ruggedinbox.com email and pay 4 Bitcoins for the decryptor.
| SUMMARY | |
| Name | N1n1n1 |
| Type | Ransomware |
| Cipher used | AES + RSA |
| Ransom size | 1-4 BTC (can be less or more) |
| Variants (extensions/prefixes) |
|
| Main dangers | Loss of personal data and/or money |
| Detection and elimination | Use FortectIntego or SpyHunterCombo Cleaner |
N1n1n1 virus belongs to the group of viruses which base their payment system on the notorious TOR network, keeping their developers’ anonymity safe. After the Locky virus swept by, the popularity of this server has significantly decreased, yet the ransomware developers seem to be getting back to using old and proven techniques all over again.
The hackers behind N1n1n1 ransomware might be just a bunch of wannabe teenagers, but that does not stop the virus from being able to inflict serious damage by locking your personal data. Currently, the criminals demand the ransomware victims to pay 4 Bitcoin for the private data decryption key — the only tool capable of deciphering the encrypted data. However, the newest variant uses an old ransom note that claims that Bitcoin is worth only $200, which is absolutely wrong (1BTC is currently worth US$6.9K).
However, we do not recommend behaving according to crooks‘ scenario because it is most likely designed to benefit them alone. Instead, you should focus on N1n1n1 removal. You will be able to eliminate the threat by running the scan with FortectIntego. It is important to eliminate the parasite at once before it entangles your entire operating system.
N1n1n1 creators do not take risks with data decryption either. They use the acknowledged AES and RSA encryption algorithms which remain undecryptable to this day. It is interesting that this type of encryption usually involves changing the file names or adding additional file extensions to the affected documents.
For instance, this particular N1n1n1 ransomware inserts a combination 8-9 randomized symbols between the original file name and the file extension, so the encrypted file may look something like this: randomfilenamejg9bl4mk.jpg. Please note: newer versions of the virus can use .n1n1n1 file extension, .999999 file extension or .jpa prefix to replace the regular ones.

After the files are encrypted, the N1n1n1 virus drops a ransom note named “How return files.txt” (other versions use different note names, such as why files renamed.txt for the jpa. version, although the contents are almost the same) on the desktop and infected folders. This file features a brief introduction of the virus and data recovery. The message starts out with a mocking advice to use a web translator for non-English speakers.
The note continues with the instructions how to download and install TOR browser. In the end, the hackers indicate the email address as their trademark logo – strongonion@sigaint.org. There are speculations that the threat might be linked to Flyper ransomware. They taunt their victims by offering to create an email account and contact them, while in the following lines, they warn that they may not receive or read victims‘ messages.
It would be unwise to follow any hackers‘ instructions and recommendations. There are few chances to recover the files even if you pay the cash, so it is better to remove n1n1n1 ransomware and try to retrieve your files some other way.
Ransomware transmission techniques and data recovery possibilities
N1n1n1 ransomware spreads like any other ransomware threat. It is suspected to disperse through spam email infections and malvertising. Malware developers are very clever and find numerous ways of tricking people into downloading the virus on their computer themselves.
For instance, they may pretend to be representatives of some governmental institution or organization and send you an email with an attached document on their behalf. When this document is opened, the virus is downloaded and activated on the computer automatically.
Additionally, virus is more likely to infiltrate system that are more vulnerable to infections, so updating all software installed is a way to prevent this infiltration technique. Keep in mind that the malware is likely to be distributed via file-sharing domains and applications. If you are not careful enough, clicking on an infected link might trigger the infection.
At the moment of writing, there is no way to decrypt the encrypted data other than by emptying your wallet for the private decryption key. Such way of data recovery is especially unfavorable also because it gives you no guarantees, while the criminals have all the control in their hands. Luckily, we are seeing some progress in data recovery software development. Tools like PhotoRec, R-Studio or Kaspersky virus-fighting utilities can be used to decrypt some data, though a full system recovery still remains an utopian idea.
Remove this destructive virus from your PC
Do not waste time and start automatic n1n1n1 removal immediately, experts[3] advise. Dealing with the threat manually might turn out to be futile and tiresome activity. Therefore, it is more convenient to download and install an anti-spyware application, for example, FortectIntego or MalwarebytesMalwarebytes, to do the elimination for you.
In the ransom note, the hackers instruct victims to disable their security programs which might hinder the installation of TOR browser. Likewise, the anti-spyware application might be your trump card to the complete termination of the cyber threat. After it successfully eliminates the n1n1n1 virus, you may start looking for programs which help to recover the encrypted files.
The ransomware itself may not look like a highly complex virus. Nonetheless, it still might cause trouble not allowing you to remove n1n1n1 that easily. In such a case, please find the access recovery guidelines displayed below.
Was this guide helpful?
3 comments