Santa Encryptor ransomware is another virus using Christmas theme

Santa Encryptor virus is a Christmas-themed ransomware virus that emerged in December 2017. In the lock screen ransom note, malware claims that files on the targeted computer are encrypted with AES-256 encryption. However, researchers tell that it might be only using XOR cryptography.
Though, the virus is still in development. However, Santa Encryptor ransomware is not the first malicious program that wants to make Christmas season terrible. Last year, the cyber community was hit by MerryChristmas ransomware that took computer users’ files to hostage too. New versions of malware were spotted this year too.[1]
According to the latest research data, Santa Encryptor is executed from ChristmasPresent.exe that might be spread as a fake program, update or malicious email attachment. Once inside, it might cause important system changes to boot with system startup, start data encryption and deliver a lock-screen message.
The ransom note imitates the design of the WannaCry; however, it has an image of the Santa Claus. It informs about data encryption and decryption, asks to send $150 to the provided Bitcoin wallet address and shows the time left for the payment:
Oop's Your File's Have Been Encrypted!
What Happened To Your PC?
Your Important File's Have Been Encrypted Many Of Your Documents, Photos, Databases And Other File's Are No Longer Accessible. Because They Have Been Encrypted Using AES-256
How Can I Decrypt My File's?
Your Lucky Santa Is Here To Help You To Decrypt Your File's With the Power Of Christmas Spirit! Santa Needs You To Send $150 Worth Of Bitcoin To The Given Bitcoin Address Below
How Do I Pay? Their Are A Few Links For You To Buy The Bitcoin, Send $150 Worth Of Bitcoin To The Given Address To Decrypt Your FIles
Send $150 Worth Of Bitcoin To This Address:
However, following the instructions appeared on the lock screen window is not recommended. The malicious program barely encrypts files at the moment. Thus, you should remove Santa Encryptor ransomware from the computer without hesitation.
Keep in mind that you are still dealing with a file-encrypting virus. Thus, you should not try to locate and eliminate ransomware-related components manually. You should complete Santa Encryptor removal with reputable malware removal software, such as FortectIntego.

Possible ways used for ransomware distribution
Cyber criminals might spread crypto-virus using:[2]
- malicious spam emails;
- fake software downloads or updates;
- illegal downloads;
- malicious ads.
These methods are widely used by other malware developers. Authors of malware apply social engineering tactics to trick people into opening obfuscated email attachment that contains malware executable or downloading fake program/update by delivering a misleading pop-up. For this reason, you should remain vigilant to avoid a cyber attack.
Malware researchers from virusi.bg[3] warn that file-encrypting viruses might also use exploit kits and take advantage of the outdated software. Thus, you should regularly update programs and operating system.
Additionally, you should still install antivirus and backup data. Modern malware is capable of bypassing even the strongest security detection. Thus, you have to be prepared for the worst.
Terminate Santa Encryptor virus and restore your files
The correct way to remove Santa Encryptor is to scan the system with FortectIntego, MalwarebytesMalwarebytes or another malware removal tool. However, the malicious program might be designed to block security tools, so you should reboot to Safe Mode with Networking or try System Restore first (instructions below).
After Santa Encryptor removal, you should be able to restore your files using third-party recovery tools or backups. Though, if you have never backed up your data, you should do that as soon as you regain yours.
Was this guide helpful?
Be the first to comment