ORCA ransomware can completely damage users' personal data using encryption algorithms

ORCA ransomware belongs to the ZEPPELIN ransomware family which was first discovered in November of 2019. The variant is capable of using complicated encryption algorithms[1] to lock users' personal files, like photos, videos, documents, etc. An infection like this can result in permanent data loss.
When the file-locking malware infiltrates the system, it starts appending files with the .ORCA.victim's_ID extension. So if a file was previously named picture.jpg, after encryption, it would look something like this – picture.jpg.ORCA.53-738-H4T. The icons are also changed to white pages so thumbnails become unavailable.
| NAME | ORCA |
| TYPE | Ransomware, file locker, crypto virus |
| MALWARE FAMILY | ZEPPELIN ransomware |
| DISTRIBUTION | Infected email attachments, torrent websites, malicious ads |
| FILE EXTENSION | .ORCA.victim's_ID |
| RANSOM NOTE | HOW_TO_RECOVER_DATA.hta |
| FILE RECOVERY | If you do not have backups, the only way to decrypt the files is by getting the key that only the hackers have. There are additional recovery options using third-party software that we cover in this article |
| MALWARE REMOVAL | The malicious program should only be removed with professional security tools to ensure all the malicious files are gone. Keep in mind that the antivirus cannot recover your data |
| SYSTEM FIX | FortectIntego maintenance tool can fix damaged files and other system errors to help victims avoid having to reinstall the operating system completely |
The ransom note
Shortly after the encryption process is done, ORCA ransomware generates a ransom note HOW_TO_RECOVER_DATA.hta on the machine. The full message reads as follows:
YOUR FILES HAVE BEEN ENCRYPTED
Your ID to decrypt: –
Contact us: GoldenSunMola@aol.com | GoldenSunMola@cyberfear.comUnfortunately for you, due to a serious vulnerability in IT security, you are vulnerable to attacks!
To decrypt files, you need to get a private key.
The only copy of the secret key that can be used to decrypt files is on a private server.
The server will destroy the key within 72h after the encryption is completed.
To save the key for a longer period, you can contact us and provide your ID!In addition, we collect strictly confidential/personal data.
This data is also stored on a private server.
Your data will be deleted only after payment!
If you decide not to pay, we will publish your data to everyone or resellers.
So you can expect your data to become publicly available in the near future!It's just a business and we only care about making a profit!
The only way to get your files back is to contact us for further instructions!
To establish a trust relationship, you can send 1 file for test decryption (no more than 5 MB)Do not waste your time searching for other decryption methods – THERE ARE NONE, you will pay more for your time!
Every day the price of decryption increases!
Do not rename encrypted files.
Do not use third-party programs to decrypt files – they can only do harm!
After payment, you get a decoder (.exe), you only need to run it, and it will do everything by itself.
I only accept Bitcoins! You can learn how to buy them on the Internet.
Ransomware developers use various scare tactics to make people act quickly. They try to pressure victims into paying a ransom. The amount is not specified in the note, which means it is most likely negotiated privately. Victims have to contact crooks within 72 hours or the decryption key will be destroyed.
Additionally, cybercriminals warn that the price will rise every day, and if not paid, they will leak private information. We urge you not to pay the ransom because threat actors cannot be trusted. Many previous ransomware attack victims say that they never received the promised decryption tools after paying.
Besides, they want to be paid in cryptocurrencies[2] because it provides anonymity. However, it is very risky for the victims. It is impossible to get the funds back once you send the cryptocurrency transaction to another wallet. Although it is almost impossible to decrypt data without the cybercriminals' help, there are third-party recovery solutions that help in some cases.

Distribution methods
Most of the time people get infected with ransomware through Torrent websites or peer-to-peer file-sharing platforms. Users often look for “cracked” software but this activity is illegal so it is unregulated. It is impossible to know if the packages you are downloading do not contain any malicious files.
Another common gateway for ransomware is email. Threat actors use social engineering[3] techniques to create convincing letters that look like urgent messages from well-known companies. In the letter, they usually include malicious links or infected attachments. It is best to only open attachments from senders you know.
To avoid malware infections in general, you should only visit websites that you know and trust. Do not click on random links and ads even if they seem to be promoting legitimate products and services. Threat actors can impersonate big tech companies and appear legitimate, so go to the source directly.
One more thing that is often overlooked, is the importance of keeping the operating system and software updated. Hackers can use software vulnerabilities to deliver their malicious programs. Software developers regularly release security patches[4] that should be installed immediately to prevent this from happening.
Remove the intruder from your machine
The first thing you have to do is remove the malicious files that are executing the tasks. If you try to recover the files without eliminating the cause, it can encrypt your files again and result in more damage. Removing the virus yourself should not be an option unless you have experience in this and know what you are doing. Use anti-malware tools like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes to scan your system.
This security software should find all the related files and entries and remove them automatically for you. Automatic removal is the best option because there is less risk of leaving some of the files on our system. Another thing to note is the malicious program could be preventing you from using the antivirus software, so check that first. If you are unable to do it, proceed with accessing Safe Mode on Windows:
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. – it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.

Windows 10 / Windows 8
- Right-click on Start button and select Settings.
- Scroll down to pick Update & Security.

- On the left side of the window, pick Recovery.
- Now scroll down to find Advanced Startup section.
- Click Restart now.

- Select Troubleshoot.

- Go to Advanced options.

- Select Startup Settings.

- Click Restart.
- Press 5 or click 5) Enable Safe Mode with Networking.

Data recovery options
Only hackers hold the decryption key, which can unlock your files, so if you did not back them up previously, you possibly lost your files forever. You can try using data recovery software, but third-party programs cannot always decrypt the files. We suggest at least trying it because it cannot hurt.
Important – only do this if you have already removed ORCA ransomware
Before proceeding, you must copy the corrupted files and place them in a USB flash drive or another external storage. In case something happens, you will at least still have the encrypted files.
- Download Data Recovery Pro.
- Double-click the installer to launch it.

- Follow on-screen instructions to install the software.

- As soon as you press Finish, you can use the app.
- Select Everything or pick individual folders where you want the files to be recovered from.

- Press Next.
- At the bottom, enable Deep scan and pick which Disks you want to be scanned.

- Press Scan and wait till it is complete.

- You can now pick which folders/files to recover – don't forget you also have the option to search by the file name!
- Press Recover to retrieve your files.

Run a maintenance tool to fix system issues
Performance, stability, and usability issues, to the point where a full Windows reinstall is required, are expected after a malware infection. These types of infections can alter the Windows registry database, damage vital bootup, and other sections, delete or corrupt DLL files, etc. Once a system file is damaged by malware, antivirus software is not able to repair it.
There are tools created just for this purpose. FortectIntego can fix a lot of the damage caused by an infection like this. Blue Screen errors, freezes, registry errors, damaged DLLs, etc., can make your computer completely unusable. By using this maintenance tool, you could try fixing the damaged system and avoid reinstallation.
- Download the application by clicking on the link above
- Click on the ReimageRepair.exe

- If User Account Control (UAC) shows up, select Yes
- Press Install and wait till the program finishes the installation process

- The analysis of your machine will begin immediately

- Once complete, check the results – they will be listed in the Summary
- You can now click on each of the issues and fix them manually
- If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.

Was this guide helpful?
Be the first to comment