Sophisticated Vanguard ransomware is yet another Golang-based virus
Today, we added Vanguard virus to the large ransomware family, but we must say that this virus differs from the rest of ransomware because it is written in Go programming language[1]. However, the first ransomware written in go was Trojan.Encoder.6491[2], however, it wasn’t as sophisticated as Vanguard ransomware appears to be. This malicious program is set to encrypt over 400 different file types, which means that its target list contains over 400 different file extensions. For data encryption, Vanguard ransomware employs Poly1305 and Salsa20 a.k.a. ChaCha20 ciphers, which are used by Google as a replacement for RC4 in TLS/SSL[3]. When encrypting the data, virus adds *нет данных* file extension to each affected file. This new extension translates to “no data.” When the virus finishes the encryption routine, it creates a ransom note for the victim and names it as DECRYPT_INSTRUCTIONS.txt. The virus asks the victim to buy a certain amount of Bitcoins and send them to a provided Bitcoin wallet, in other words, to pay a ransom. They promise to provide a data recovery tool in return, but no one knows if these crooks are as good as their word. Some ransomware crooks just take victim’s money and make off with it, while others ask for more money. 
No matter how disappointed we are to say this, it is likely that this ransomware won’t be cracked anytime soon. It would take years of brute-forcing to discover just one decryption key due to the complexity of encryption ciphers that Vanguard ransomware uses. Therefore, we suggest you remove Vanguard ransomware immediately and start looking for your backup[4]. You can easily delete the ransomware using tools like FortectIntego or SpyHunterCombo Cleaner, but please do not try to do it manually because you can inadvertently damage the computer system by removing the wrong files. We also know that this virus runs the following command – vssadmin delete shadows /all /quiet, which eliminates Windows Volume Shadow Copies[5], and as a result, you won’t be able to use them for data recovery. This powerful virus opens security vulnerabilities in your computer, so please take care of this problem ASAP. You should take a look at full ransomware removal guide given below this article and learn how to prepare your PC for Vanguard removal.
What methods are used for ransomware distribution?
Ransomware viruses are mainly distributed via RDP attacks, email spam and exploit kits. Sometimes, ransomware gets into computers with the help of malware-laden ads, but in general, criminals are not eager to waste their time hacking ad networks when they can simply send out thousands of convincing email messages that victims typically tend to open. For example, cyber criminals create a malicious Word document that contains a special script meant to download and install ransomware on the system. They only need to save this file under a innocent-looking name, for example, “Invoice” or “resume.” Such file greets the victim with a message saying, “Macros have been disabled” and suggests enabling content. If the victim clicks this button, the script gets activated and the computer gets infected with ransomware. So far such documents remain the most popular ransomware distribution tools, and users still fall for this trick.
How can I fix my computer and remove Vanguard ransomware from the system?
When one gets infected with ransomware, the first thing he or she should do is to remove the virus from the compromised PC. Sadly, we doubt that ransomware crooks can help you with data decryption – they do their best trying to force victims to pay ransoms, but we are sure that they can not care less about you from the moment they get what they strive for. Therefore, we do not recommend paying the ransom and suggest using FortectIntego or other reliable tools for Vanguard removal. You can try one of the provided data recovery methods described below.
Did this guide help?
3 comments
Henrix
Thanks for the help. Vanguard virus infected my PC yesterday, but i had a backup. I just had to remove it and thats it!
Josephine
Here we go.... another Golang malware
luke_!
My files are corrupted! Theres no words to express my disappointment! What have i done! I lost all of my files in less than 5 minutes!