Spartacus ransomware is a crypto-virus that uses hard-coded RSA encryption

Spartacus ransomware is a dangerous virus that was spotted for the first time in the middle of April 2018. It is closely related to the SF.exe file, which may be injected into spam emails, rogue software updates, or installed on the system using brute-force attacks via unprotected Remote Desktop services.[1] It encrypts files using a combination of AES and guard-coded RSA.[2] ciphers. Upon encryption, locked files get .Spartacus or [MastersRecovery@protonmail.com].Spartacus file extension, while the relevant information about the attack can be found on a READ ME.txt file.
| Name | Spartacus |
|---|---|
| Classification | Ransomware |
| Danger level | High. Corrupts system's settings, locks personal files with hard-coded cipher, demands to pay a ransom |
| Symptoms | Personal files inaccessible. Each of them exhibits an unusual file extension |
| File extensions used | .Spartacus or [MastersRecovery@protonmail.com].Spartacus |
| Encryption model | A combination of AES and RSA |
| Decryptable | No |
| Download FortectIntego to eliminate Spartacus completely | |
Ransomware researchers detected SF.exe file circulating on the Internet and revealed it to be the executable of a Spartacus ransomware. If the potential victim runs the file, the virus unravels the payload and initiates the following Windows OS modifications:
- Launches Command Prompt using administrative privileges and runs scripts to delete Volume Shadow Copies (cmd.exe / c vssadmin.exe delete shadows / all / quiet);
- Runs a hard-coded encryptor (AES – RSA) and runs a key generator to create a unique victim's ID;
- Creates Test mutex to make the system immune to repeated Spartacus ransomware attack;
- Enables SetForegroundWindow function to display lock screen;
- Creates a ransom note called READ ME.txt on the desktop;
Spartacus malware does not target files according to their extensions. Instead, it attacks particular system's folders and directories. That's the list of system's locations targeted by Spartacus crypto-ransomware:
- System
- ProgramData
- Desktop
- MyComputer
- DesktopDirectory
- Favorites
- Personal
- MyMusic
- History
- Personal
- Downloads
- Documents
- Pictures
- Videos
- Music
Once the virus renders the data inaccessible by appending .Spartacus or [MastersRecovery@protonmail.com].Spartacus file extension, the ID KEY is created and provided on the ransom note. The victim subsequently is urged to write an email message to MastersRecovery@protonmail.com or MastersRecovery@cock.li and indicate the unique identification number to get payment instructions.
All of your data has been locked us.
You want to return?
Write email MastersRecovery@protonmail.com or MastersRecovery@cock.li
Your personal ID KEY: XXXX
The same notification shows up in the form of a lock screen.
Crooks demand to pay the ransom in Bitcoins, while the size of redemption is said to differ according to how fast the victim contact them. Experts claim that the sum of the ransom Spartacus demands varies from 300 to 500 USD.
The ransom note contains intimidating information urging victims not to try decrypting files manually or using third-party software recovery tools. Currently, it's not known whether it's capable of deleting the files permanently, but we believe that it's possible as long as you do not perform Spartacus ransomware removal.

We would strongly recommend you not to pay the ransom because any support for hackers motivates them to initiate further attacks. Besides, it's not clear whether criminals have a working decryptor either. At best, you should remove Spartacus ransomware and try to recover your files using third-party data recovery programs. To get rid of ransomware infection, use a reliable security tool, such as FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.
Unsafe browsing behavior is the most common culprit of ransomware attacks
The characteristics of this ransomware are not distinctive from other ransomware family members. It attacks users unexpectedly, encrypts personal files, and demands to pay the ransom in the digital currency. Distribution technique is not unique either. As pointed out by NoVirus.uk.[3] cybersecurity research team, to protect the system from this ransomware it's a must to bypass suspicious emails without opening their attachments.
Some of the emails, indeed, can look trustworthy or catchy. However, keep in mind that cybercriminals are specialists of various social engineering strategies, which is why they know how to mimic public authorities, such as IRS, Amazon, Windows, Apple, and similar.
The distinctive feature of spam emails is an attachment (or link), which is disclosed as a document, pdf file, image or another popular file type. Note that such attachments will require enabling Macros to read the content. That's a catch, so do not allow macros under any circumstances unless you opt for downloading ransomware.
However, spam is not the only ransomware distribution method. Currently, crooks exploit unprotected Remote Desktop Services or create fake software updates, so it's essential to browse the Internet safely. Do not forget to keep anti-virus updated and always enabled.
Learn how to remove Spartacus in a few clicks
Spartacus ransomware removal is the best option you have. Run a full system scan with FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes and get rid of all malicious components. Paying the ransom is a mistake because the intentions of cybercriminals may be more aggressive than you thought. They might send you a worm or spyware instead of a working Spartacus decryptor.
Once you remove Spartacus virus from the system, try to recover your files with the help of third-party tools or use Windows Recovery feature.
Did this guide help?
Be the first to comment