FBI Ransomware Has Messy Ransom Notes

ransomware

FBI ransomware is the name of yet another newly discovered strain of ransomware. This particular variant seems to have been put together pretty sloppily.

The FBI ransomware, which needless to say has nothing to do with the FBI and is operated by hackers, will encrypt files on the victim system, appending the ".fbi" extension to them. This will affect most file extensions, including media, document, executable and archive files.

When encryption completes, the ransomware creates three separate files, seemingly intended to contain the ransom note, called "LOCKEDBYFBI.hta", "readme.txt" and "decryptfiles.html". All three of those are blank and contain no text or meaningful information, which may imply an inexperienced hacker behind the ransomware.

The desktop wallpaper is changed to a static image containing the actual ransom note and a synthetic voice reads it out to the victim. The premise of the ransom note is a silly one to use in 2022. The hackers attempt to persuade the victim that their system has been locked by the FBI because the victim has "illegal content" on their system.

Similar scary and obviously fake messages were used years ago and have since gone out of fashion. The full note goes as follows:

Illegal content has been found on your system!

This computer has been seized by the Federal Bureau of Investigation.

Inn accordance with a seizure warrant obtained by the U.S. Attorney's Office for the Southern District of California, and the U.S. Department of Justice, Criminal Division, Computer Crime and Intellectual Property Section.

Issued pursuant to 18 U.S.C. §§ 981, 982, and 1030 by the United States District Court for the Southern District of California.

All your files have been encrypted and to get them back you must notice we detected illegal content.

We notice also your illegal activity online, to get your files back you must e-mail us at crimeinvest23 at proton dot me

Else your files will be used as evidence against you. Your fine must be payed and illegal files will be erased after.

Your current find is: $250.00 for having illegal websites and activity in your system.

Do not attempt to close the locker, it is bad decide for you. When closed all detail will be sent to the FBI database.

You can be arrested for up to many years and its classed as escaping the fine.

Warning, all attempts to unlock the system are logged to FBI database, do not try to guess your system password, pay the fine!

October 13, 2022
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.