WORK ransomware is the latest version of CryptoMix

WORK virus is a file-encrypting malware that belongs to well-known ransomware group CryptoMix. The recent cyber threat uses a combination of RSA-2048 and AES CBC 256-bit encryption and appends .WORK file extension. Additionally, it renames targeted files with 32 random letters and numbers. Thus, files become messy after the attack.
Following data encryption, WORK ransomware creates a “_HELP_INSTRUCTION.TXT” file in each folder that contains encrypted data. It provides data recovery instructions and unique victim’s ID which users have to send to all provided email addresses:
- worknow@keemail.me;
- worknow@protonmail.com;
- worknow8@yandex.com;
- worknow9@yandex.com;
- worknow@techie.com.
Thus, this WORK CryptoMix follows the same ransomware family’s behavior. The full text of the ransom note:
Attention! All Your data was encrypted!
For specific informartion, please send us an email with Your ID number:
worknow@keemail.me
worknow@protonmail.com
worknow8@yandex.com
worknow9@yandex.com
worknow@techie.com
Please send email to all email addresses! We will help You as soon as possible!
IMPORTANT: DO NOT USE ANY PUBLIC SOFTWARE! IT MAY DAMAGE YOUR DATA FOREVER!
DECRYPT-ID-XXX
Nevertheless, cyber criminals try to scare that files will be lost if victims do not follow the instructions; security experts do not recommend having business with evil-minded people. You might not only lose your data but money as well.
There’s no doubt that criminals will ask to pay a ransom in Bitcoins.[1] However, there are no guarantees that once you make a transaction, you will receive a working decryption key. Thus, after WORK ransomware virus attack, you should focus on cleaning your PC from this cyber threat.
Bear in mind that you are dealing with a dangerous crypto-virus that is capable of making sever changes to the computer, such as creating Windows registry keys[2] or injecting malicious code into legitimate processes. Thus, WORK ransomware removal is needed to continue using a computer without hackers breathing behind your back and risking to lose new files or even personal data.
However, do not try to remove WORK virus manually. As we have mentioned, it’s a complicated infection. Thus, you should use FortectIntego or another malware removal tool to delete all ransomware-related components safely.

Criminals remain loyal to the same distribution methods
Usually, CryptoMix family spreads via malicious spam emails. Such letters often pretend to be important or sent from a well-known organization. They always contain malicious attachments which include malware payload. It is dropped on the system as soon as a victim opens such file.
However, malware might also be spread via malware-laden ads that might be placed on legitimate or potentially dangerous websites. It might also be presented as a useful program on various file-sharing sites or networks. Thus, users are advised to be critical about the content they click online no matter where they live – Germany,[3] the United States or Japan – WORK ransomware might reach you wherever your computer is located.
Termination guide of the .WORK file virus
We have already told you that WORK virus removal is completed using reputable malware removal tools. Our team recommends using FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes; however, you can use your preferred software as well. The most important part is that you have to use updated program that is capable of detecting recent cyber infections.
However, you should also reboot the computer to Safe Mode with Networking or try System Restore method that allows disabling the virus. Malware might be resistant and block antivirus software. Thus, you have to complete additional steps to remove WORK ransomware entirely. Follow the guide below.
Was this guide helpful?
Be the first to comment