Raa-consult1@keemail.me ransomware: what it is and how to recover

Raa-consult1@keemail.me ransomware, better known as RAA, is a script file that encrypts your documents, renames them to .locked and installs the Pony password stealer. No free decryptor is known, so remove it, change your passwords and restore from copies.

Facts checked October 5, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Before you restore backups, a full scan can confirm the program that added .locked is gone.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove RAA ransomware yourself 6 steps, about 18 minutes, no software needed.

Start the steps
Russian ransom note of the RAA virus with the e-mail address raa-consult1@keemail.me marked, and a WordPad window titled doc_attached_Cnlj4 showing the fake error 0034832
Our 2016 picture: the Russian note, and in front of it the WordPad window with the fake "error code 0034832" and a block of base64 text (the title banner is report artwork).

RAA ransomware: summary

TypeScript-based ransomware: encrypts documents and photos, adds .locked, installs the Pony stealer
RiskHigh: no known free decryptor, and stored passwords may be stolen
SymptomsFiles renamed .locked, !!!README!!![ID].rtf on the desktop in Russian, a WordPad window with a fake error 0034832
How to get rid of itDisconnect, scan with Microsoft Defender, delete the .js file, st.exe and the Run entry, change passwords elsewhere
Our checkSource check on 5 October 2026 and one visit to keemail.me on 4 October 2026; malware not run
First seen13 June 2016 (BleepingComputer); our first report 20 September 2016
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 14 more facts
NameRAA ransomware (also Raa-consult1@keemail.me ransomware)
Encrypted file extension.locked
Ransom note!!!README!!![ID].rtf in Russian, quoted below without the payment address
DecryptorNone known; not on the No More Ransom list
Contactraa-consult1@keemail.me and a Bitmessage address
Detection namesMicrosoft: Ransom:JS/CryptoRaa.A for the script. No Microsoft detection name is known for the dropped Pony file st.exe (not confirmed)
DistributionE-mail attachments ending .js with a document-like name
DamageEncrypted documents and images, removed shadow copy service, Pony stealer
Evidence0 write-ups by security sites; no sample analysed yet
Encrypted files.locked
Attacker contactsraa-consult1@keemail.me
Free decryptorNo free decryptor is known (checked 5 October 2026)
Microsoft Defender nameRansom:JS/CryptoRaa.A
Facts checked5 October 2026

Facts checked on 5 October 2026 against BleepingComputer's and Emsisoft's 2016 analyses, Tripwire, PCrisk's 2021 update and the No More Ransom tools list; keemail.me visited once on 4 October 2026. We did not run the malware.

What the Raa-consult1@keemail.me ransomware is

"Raa-consult1@keemail.me" is the e-mail address in the ransom note of RAA, a Windows ransomware written as a script file: it encrypts documents and photos, adds .locked to their names and installs the Pony password stealer.

Our 2016 report said it arrives as a Word document that needs macros. The sources show a .js script file with a document-like name instead; the corrections are marked below.

Also called
RAA ransomware, RAA virus, RAA-SEP (BleepingComputer's help topic)
Written as
A script run by Windows Script Host, with the CryptoJS library inside
First seen
13 June 2016 (BleepingComputer); our first report 20 September 2016
Extension and note
.locked; !!!README!!![ID].rtf in Russian
Price in the note
0.39 Bitcoin, about 250 US dollars in 2016
Extra payload
Pony password stealer, saved as st.exe in Documents

How the RAA story went

  1. 13 June 2016

    First public report

    BleepingComputer describes RAA, found by two researchers who tweet as JAMESWT_MHT and benkow_, as ransomware made of a script file, not a program.

  2. 15 to 26 June 2016

    Pony, the fake document and a Microsoft name

    Emsisoft shows Pony inside the script and says decryption "is currently not possible". BleepingComputer adds the Windows Script Host advice. Microsoft publishes Ransom:JS/CryptoRaa.A on 26 June.

  3. 20 September 2016

    Our first report

    We described a Word document with macros and a 250 dollar demand. Our picture, at the top of this page, shows the Russian note and the fake error window.

  4. 20 December 2021

    PCrisk update

    PCrisk still says no tool could restore RAA files.

  5. 5 October 2026

    Our recheck

    No More Ransom lists no RAA tool, and keemail.me answered and sent us on to another domain. We rewrote the guide from these sources.

What we checked and what we did not

We visited the domain in the note's address once and read the analyses. We did not run the malware.

keemail.me and RAA · check · 4 and 5 October 2026

  • Site answerkeemail.me answered 200 and sent our browser on to tuta.com, an encrypted e-mail service. One visit from Lithuania, Chromium.
  • Notifications, pop-ups, adsNone seen on that visit; no service worker.
  • The mailboxWe cannot see whether the address in the note is still read. The .me registry has no RDAP server, so no registration date.
  • DecryptorNo RAA entry on the No More Ransom list (5 October 2026).
  • Files and registryFrom Microsoft and BleepingComputer; not tested on a live infection.

Nothing on this one visit One visit proves little. The danger is the script and Pony on the PC, not visiting keemail.me.

Which name will your scanner show?

Microsoft's name for RAA ransomware is Ransom:JS/CryptoRaa.A.

Defender sorts threats by category first, so the word before the colon tells you what kind of program was found, even if the family name means nothing to you.

Do not search for a removal tool by the detection name alone; fake "removal tools" use the same keywords. How the naming works is explained in our guide to antivirus detection names.

  • File extension: .locked
  • Note file: !!!README!!![ID].rtf
  • Contact: raa-consult1@keemail.me

How RAA ransomware behaves

What it does on the PC, step by step

The order comes from the BleepingComputer, Emsisoft and Microsoft descriptions of the 2016 script; later copies may differ.

  1. 1

    You open the attachment

    Windows hands a .js file to Windows Script Host (wscript.exe), which runs scripts outside a browser.

  2. 2

    A fake broken document opens

    A file named like doc_attached_[random letters] is saved in Documents and opened in WordPad, with a Russian error 0034832 saying the document needs a newer Word. You think the attachment is damaged.

  3. 3

    A startup entry is added

    A Run value in the registry points at the script, so it starts at every sign-in and can encrypt documents you create later.

  4. 4

    The shadow copy service is removed

    Emsisoft saw the Volume Shadow Copy service deleted, so Previous Versions shows nothing. BleepingComputer is not sure the copies themselves are deleted.

  5. 5

    Files are encrypted

    It picks the file types it wants on every drive it can write to and encrypts them with AES through CryptoJS, adding .locked. Microsoft says no internet connection is needed for this.

  6. 6

    Pony and the note

    The script decodes Pony to st.exe in Documents and runs it, then writes the note to the desktop. The note says a README also sits in the root of each drive.

Which files and folders it touches

Sixteen file types only, so videos, music and installers are not on the list, although the 2016 guide counted videos.

Types it encrypts (BleepingComputer, Emsisoft, Microsoft, PCrisk)

  • .doc
  • .xls
  • .rtf
  • .pdf
  • .dbf
  • .jpg
  • .dwg
  • .cdr
  • .psd
  • .cd
  • .mdb
  • .png
  • .lcd
  • .zip
  • .rar
  • .csv

Folders it skips

  • Program Files
  • Program Files (x86)
  • Windows
  • Recycle.Bin
  • Recycler
  • AppData
  • Temp
  • ProgramData
  • Microsoft

It also skips any file whose name contains .locked, ~ or $. Documents saved as .docx or .xlsx are not in the published list either; later copies of the script may differ.

What the ransom note demands

The note asks you to write first, test one file, then pay 0.39 Bitcoin.

From the English translation of the note published by BleepingComputer.
ItemWhat the note saysWhat it means
ClaimAES-256, "used to protect state secrets"Real cipher, sales line. Code readers found AES from CryptoJS; PCrisk's "RSA" is not what they found.
First stepSend your ID to raa-consult1@keemail.meThe ID ties your PC to their records. A free mailbox is all they need.
ProofDecrypt a few files as a testProves they hold something, not that the rest works
Price0.39 BTC, written as 250 US dollarsWe do not print the payment address
DeadlineKeys of unpaid victims removed within a weekPressure; nothing outside the note supports it
Backup contactBitmessage, if no reply in 3 hoursA network with no central owner, so the address cannot be taken down

Was anything stolen? The Pony stealer

Possibly: Pony steals stored passwords, and RAA starts it at every sign-in, so treat passwords on this PC as exposed.

  • High

    Stored passwords

    Emsisoft and Tripwire describe Pony as able to steal passwords and send them to an attacker.

  • Medium

    Accounts you used here

    Change your e-mail password first from another device, then banking and shops.

  • Low

    No leak site

    No source mentions a threat to publish files.

The RAA ransomware note

a ransom note left in folders

*** ATTENTION! ***

Your files have been encrypted virus RAA.

For encryption was used algorithm AES-256 is used to protect information of state secrets.

This means that data can be restored only by purchasing a key from us.

Buying key - a simple deed.

All you need to:

1. Send your ID [victim ID] to the postal address raa-consult1@keemail.me.

2. Test decrypt few files in order to make sure that we do have the key.

3. Transfer 0.39 BTC ($ 250) to Bitcoin-address [address omitted].

For information on how to buy Bitcoin for rubles with any card - [Russian exchange site].

4. Get the key and the program to decrypt the files.

5. Take measures to prevent similar situations in the future.

Importantly (1). Do not attempt to pick up the key, it is useless, and can destroy your data permanently.

Importantly (2). If the specified address (raa-consult1@keemail.me) you have not received a reply within 3 hours, you can use the service for communication Bitmessage.

Importantly (3). We CAN NOT long keep your All keys, for which no fee has been paid, are removed within a week after infection.

README files located in the root of each drive.

Can RAA ransomware files be decrypted?

We found no free way: Emsisoft (2016), BleepingComputer and PCrisk (2021) say the files cannot be restored without the key, and No More Ransom has no tool.

Do

  • Keep a few .locked files and the note on a USB drive in case a tool appears
  • Check the No More Ransom list again later; ID Ransomware can confirm the family

Don't

  • Do not rename .locked away; it changes nothing inside
  • Do not download a "free RAA decryptor" from a search result
  • Do not write to the address in the note

How to remove RAA ransomware

Tools you'll need

All of these are free except where noted. Download them on a clean device if the infected PC is offline.

  • A USB stick: to keep the ransom note, two or three encrypted files and screenshots off the infected PC.
  • Microsoft Defender Offline: built into Windows 11 and Windows 10; scans before Windows starts, so running malware cannot hide.
  • Microsoft Safety Scanner: a second, portable scanner with current signatures; each download works for 10 days.
  • ID Ransomware: identifies the family from the note and one encrypted file and says whether a decryptor exists.
  • No More Ransom: the free decryptors from police and security companies; check it again every few months.
  • Fortect (optional): scans Windows for malware and repairs the system files and settings it damaged. The free scan is in the box above.

How to remove RAA ransomware and get your files back

Work in this order.

Disconnecting comes first, removal comes before any restore, and nothing here asks you to contact the attackers.

  1. Step 1: Disconnect the PC and unplug backup drives

    RAA ransomware encrypts everything it can reach, including drives and shares you connect later. Cut the network first: cable out, or Wi-Fi off from the taskbar.

    Then unplug every USB stick and backup disk and pause cloud sync, so the encrypted versions do not replace your online copies. Do not reconnect any of them until the ransomware is removed from the Windows 11 or Windows 10 PC.

    Windows 11 quick settings with Wi-Fi turned off
    Windows 11: turn off Wi-Fi to take the PC offline.

    Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files

  2. Step 2: Save the ransom note and confirm the family

    Copy !!!README!!![ID].rtf and one or two files ending in .locked to a USB stick, and leave the originals where they are.

    From another device, upload the note and a sample file to ID Ransomware or No More Ransom's Crypto Sheriff, which name the family from the note, the extension and the file structure.

    Write down the contact address and your personal ID from the note, because a decryptor or the police may ask for them.

    Warning: Never contact the attackers from the infected Windows 11 or Windows 10 PC.

    A ransom note text file next to encrypted files in File Explorer
    Windows 11: the ransom note and encrypted files to copy for identification.

    Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files

  3. Step 3: Check for a free decryptor

    For RAA ransomware, no free decryptor is known (checked 5 October 2026). Search the family name in the No More Ransom decryption tools list and in the free decryptors of Emsisoft, Avast and Kaspersky, because new tools appear years after an attack.

    Important: Keep the encrypted files even if nothing works today, and do not pay before every free option is ruled out: payment does not guarantee a working key.

    Decryptors run on Windows 11 and Windows 10, but only after the ransomware itself is removed.

    Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files

  4. Step 4: Remove the ransomware before you restore or decrypt

    Restoring or decrypting files while RAA ransomware still runs lets it encrypt them again. Run a Full scan in Windows Security > Virus & threat protection > Scan options, then the Microsoft Defender Antivirus (offline scan).

    If the ransomware blocks Windows Security, start Safe Mode with Networking and scan from there. Some families install a password stealer as well, so let both scans finish on Windows 11 or Windows 10.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Look for shadow copies of the files

    Open Command Prompt as administrator and run vssadmin list shadows. If it lists copies dated before the attack, right-click a folder with encrypted files in File Explorer, choose Properties > Previous Versions, and open or restore a version from before that date.

    ShadowExplorer, a free tool, shows the same copies when the tab is empty or hidden. Most current families delete shadow copies, so an empty list is normal, but the check takes two minutes on Windows 11 or Windows 10.

    Command Prompt running vssadmin list shadows
    Windows 11: vssadmin list shadows shows whether shadow copies exist.

    Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files

  6. Step 6: Restore the files from a backup or recover deleted originals

    Restore from an external backup, File History or OneDrive's version history, choosing a date before the attack. Connect the backup drive only after the scans are clean, or the ransomware encrypts it too.

    If there is no backup, file recovery software can sometimes find the deleted originals, because some ransomware writes an encrypted copy and deletes the original file.

    Stop writing to the drive and try recovery on Windows 11 or Windows 10 before new files overwrite the space.

    Full procedure with screenshots: Recover deleted files (Recycle Bin, backups, OneDrive) On uGetFix

Report it and recover your files

Report it

Report the attack even if you do not expect the files back: insurers and banks ask for the report number, and police use the contacts in the note to link cases.

United States
FBI IC3 · FTC ReportFraud

Give the victim ID, the note and the date the files were encrypted. A business that holds personal data may also have to notify its data protection authority, in the EU within 72 hours.

Ways to get files back without the key

Look for copies, in this order, and save nothing new to the disk meanwhile.

  1. 1

    Backups

    An external drive, NAS or cloud copy; connect it only after the PC is clean. Follow the 3-2-1 rule for the future: three copies, two kinds of storage, one away from the PC.

  2. 2

    Forgotten copies

    E-mail attachments, a phone, a USB stick, a messenger, a cloud drive's version history. The 2016 guide named e-mail and USB drives.

  3. 3

    Previous Versions and shadow copies

    Right-click a folder, Properties > Previous Versions (Windows 11: Show more options first). Emsisoft says the service is deleted, so expect nothing, but vssadmin list shadows in an administrator Command Prompt shows whether copies survived.

How to prevent RAA ransomware and the next attack

RAA needs one thing: you open a script file.

  1. 1

    Show file extensions

    File Explorer: View > Show > File name extensions, so a .js ending cannot pass as a document.

  2. 2

    Turn off Windows Script Host (optional)

    BleepingComputer's advice: under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings create a DWORD Enabled set to 0. Scripts then stop running outside the browser. Not confirmed by us on Windows 11 or 10, and it blocks your own .js files too.

Do

  • Update Windows and programs, and use Microsoft Defender
  • Save attachments first so the antivirus can scan them
  • Delete unexpected e-mails, above all with .js attachments

Don't

  • Do not enable macros because a document asks; RAA does not need them, other malware does
  • Do not install programs from pop-up ads or redirects

Questions about RAA ransomware

How do I open .locked files?

You cannot open them. RAA encrypts each file with AES and appends .locked, so test.jpg becomes test.jpg.locked and only the criminals' key can turn it back.

Renaming the file to remove .locked changes nothing inside it, and no program can read the content without the key. What you can do is open copies:

  • a backup
  • an e-mail attachment you sent
  • a phone
  • cloud version history

Keep the .locked files, because a tool may appear later. Files RAA does not target, such as videos, are probably readable already.

Is there a decryptor for RAA ransomware?

No free decryptor is known. Emsisoft wrote in June 2016 that decryption was not possible, BleepingComputer found no way, and PCrisk's December 2021 update says only a backup helps. The No More Ransom tools list, read on 5 October 2026, has no RAA entry.

Be careful with sites offering a free RAA decryptor, which often carry more malware. Keep copies of a few .locked files and the note, and check ID Ransomware and No More Ransom again every few months.

Should I pay the RAA ransom?

No. The note asks you to send your ID to a free mailbox, test a few files, then send 0.39 Bitcoin. Nothing we read says that payers received a working decryptor, and PCrisk expects criminals to ignore victims after payment.

The one-week deadline is pressure, not a technical fact. Paying also does not remove Pony, which may already hold your passwords. Spend the time changing passwords from a clean device and looking for copies of your files.

Do paid decryption services work for RAA?

They cannot do what the criminals' key does. Without the key, a service has nothing to decrypt with, and a firm that promises results is guessing or will pay the criminals for you, which does not reduce your risk.

Real help is restoring from copies. Recovery tools for deleted files rarely help here, because the sources describe RAA encrypting files and do not describe deleting the originals. Ask any service in writing what exactly it will do before you pay.

How did RAA get on my PC?

Almost certainly you opened an e-mail attachment that was really a script file. BleepingComputer saw names like mgJaXnwanxlS_doc_.js and Tripwire says it was sent as an attached JS file. Windows hides file endings by default, so the name looks like a document.

Our 2016 guide said it was a Word file that needed macros; the analyses do not show that. Look in your mail and Downloads for a .js file with a document-like name, and keep it for the scan.

Was my data stolen by RAA?

Possibly. RAA carries the Pony stealer as encoded text, writes it to Documents as st.exe and starts it at every sign-in. Emsisoft says Pony can steal stored passwords and send them to an attacker.

No source mentions a leak site or a threat to publish your files. Change your e-mail password first from another device, then banking, shops and social accounts, turn on two-step sign-in, and watch your bank statements for charges you do not know.

What is keemail.me?

keemail.me is the domain of the address in the note. When we opened it on 4 October 2026 it answered normally and sent our browser on to tuta.com, an encrypted e-mail service, with no notification request, pop-up or ad network. That was one visit, so it proves little.

The address is a mailbox the criminals used to receive your ID. We cannot tell from outside whether it still works, and you should not write to it. Visiting the site does not infect you; opening the .js attachment does.

How is RAA different from other .locked ransomware?

Several families add .locked, so the ending alone proves nothing. RAA is identified by the note !!!README!!![ID].rtf in Russian, the address raa-consult1@keemail.me, the fake WordPad error 0034832, and st.exe in Documents.

It is also a plain script file rather than a program, unlike Ransom32, which was packed into an executable. Microsoft detects it as Ransom:JS/CryptoRaa.A. If your note, address or file names differ, you have another family and our steps may not fit.

How do I remove RAA from Windows 11 or 10?

Disconnect the PC from the network, start Windows in Safe Mode and run a full scan with Microsoft Defender, including an offline scan, as Microsoft advises for this threat. Then check the places the analyses list:

  • delete st.exe in Documents
  • the .js attachment
  • the startup value in the Run registry key that points to it

Our removal plan below gives the menu paths for Windows 11 and 10. Removal does not bring files back, so restore from a backup afterwards, only once the PC is clean.

Will Fortect remove RAA ransomware?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For RAA ransomware, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Questions and experiences: RAA ransomware

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year