Published: August 31, 2026 Category: Removal guides
1. HMDL Ransomware
What kind of malware is HMDL?
HMDL is ransomware discovered by our researchers during a routine inspection of new submissions to the VirusTotal website. It encrypts files on the victim's computer, making them impossible to open.
Unlike most ransomware, HMDL does not append any extension to the files ...
Published: August 30, 2026 Category: Removal guides
2. Aldet Ransomware
What kind of malware is Aldet Ransomware?
Aldet is ransomware our research team identified during a routine inspection of new submissions to the VirusTotal website. It encrypts files, appends a unique victim ID, the attackers' email address, and a ".aldet" extension to filenames, drops a ransom note, ...
Published: August 26, 2026 Category: Removal guides
3. Fiasco Ransomware
What kind of malware is Fiasco Ransomware?
Fiasco Ransomware is ransomware that our research team found while inspecting new submissions to VirusTotal. It encrypts files, appends the ".secure" extension to their filenames, and drops a ransom note. The attackers also claim to steal sensitive data before ...
Published: August 23, 2026 Category: Removal guides
4. Grandeur Ransomware
What kind of malware is Grandeur?
Grandeur is ransomware found by our research team during a routine inspection of new submissions to VirusTotal. It belongs to the VoidCrypt ransomware family and encrypts victims' files, demanding payment for their recovery.
On our test machine, this ransomware encrypted ...
Published: August 19, 2026 Category: News
5. Ransomware Affiliate Poses As Fake 'Ransom Busters' Recovery Firm
A threat actor operating under the name "Ransom Busters" is contacting ransomware victims directly, posing as an independent recovery service that can delete stolen data and provide decryption keys in exchange for payment. Security researchers now believe the entity is not a legitimate third party at ...
Published: August 17, 2026 Category: News
6. Clop Ransomware Hits Philips, GE, And Shell
Industrial and energy giants Philips, General Electric (GE), and Shell have all confirmed they are investigating claims made by the Clop ransomware gang that it stole data from their systems. The disclosures follow a wider extortion campaign in which the cybercrime group exploited a critical vulnerability ...
Published: August 16, 2026 Category: Removal guides
7. KIMO Ransomware
What kind of malware is KIMO Ransomware?
KIMO is ransomware our researchers discovered while analyzing new malware samples submitted to VirusTotal. It encrypts files using AES-256-CTR and appends the .KIMO extension to every file it locks.
On our test machine, this ransomware encrypted files and ...
Published: August 16, 2026 Category: Removal guides
8. KarryTech Ransomware
What kind of malware is KarryTech?
KarryTech is ransomware that our researchers discovered while examining new file submissions on VirusTotal. It encrypts files stored on the victim's machine and demands payment in exchange for a decryption tool.
On our test machine, KarryTech appended each encrypted ...
Published: August 16, 2026 Category: Removal guides
9. Betelgeuse Ransomware
What kind of malware is Betelgeuse ransomware?
Betelgeuse is ransomware our team discovered during a routine inspection of new submissions to the VirusTotal website. It targets company networks, encrypts files, and demands payment in exchange for a decryption key. It also claims to exfiltrate sensitive ...
Published: August 12, 2026 Category: Removal guides
10. MAJINAHANASHI Ransomware
What kind of malware is MAJINAHANASHI?
MAJINAHANASHI is ransomware our researchers discovered while examining new malware samples submitted to VirusTotal. It encrypts files, appends the .majin extension to their names, and drops a ransom note in a text file named README.txt. The attackers also claim ...
Published: August 11, 2026 Category: Removal guides
11. FLocker Ransomware
What kind of malware is FLocker Ransomware?
FLocker is a ransomware-type program that our researchers analyzed while reviewing malware samples submitted to VirusTotal. It encrypts victims' files, renames them using Base64 encoding, appends the .Flock extension, and changes the desktop wallpaper.
On ...
Published: August 11, 2026 Category: News
12. DeadLock Ransomware Uses Blockchain To Dodge Takedowns
A ransomware operation tracked as DeadLock has built its victim-communication and data-leak systems around blockchain technology, making the group's infrastructure considerably harder for defenders and law enforcement to dismantle. Security researchers first flagged the technique in a report published ...
Published: August 11, 2026 Category: Removal guides
13. ZAWOOO Ransomware
What kind of malware is ZAWOOO?
ZAWOOO is ransomware our research team discovered while examining new malware samples submitted to VirusTotal. It encrypts victims' files and renames them to random strings, replacing both the original filename and extension with random characters. The attackers also ...
Published: August 10, 2026 Category: Removal guides
14. Montage Ransomware
What kind of malware is Montage?
Montage is a ransomware-type program that we found while inspecting new submissions to the VirusTotal website. It encrypts files, appends its own extension to their names, and drops a ransom note. Montage is identical to Developer and Friends ransomware.
On our test ...
Published: August 06, 2026 Category: Removal guides
15. UMBRA Ransomware
What kind of malware is UMBRA Ransomware?
UMBRA is ransomware discovered by our researchers during a routine inspection of new submissions to VirusTotal. It encrypts files on the victim's computer, appends the ".umbra" extension to their filenames, drops a ransom note named "README_[victim_ID].txt", ...
Published: August 04, 2026 Category: Removal guides
16. Vitya Ransomware
What kind of malware is Vitya Ransomware?
Vitya Ransomware is ransomware that locks victims' files and demands payment for decryption. It appends the .vitek extension to encrypted filenames and displays a pop-up window containing the ransom demand and a countdown timer.
On our test machine, Vitya ...
Published: August 02, 2026 Category: Removal guides
17. Kreepr Ransomware
What kind of malware is Kreepr Ransomware?
Kreepr is ransomware that our research team discovered while examining new samples submitted to the VirusTotal website. It encrypts victims' files using AES-256-GCM and presents its ransom demands through a pop-up window. Unlike most ransomware, Kreepr provides ...
Published: August 02, 2026 Category: Removal guides
18. PicMo Ransomware
What kind of malware is PicMo?
PicMo is ransomware our research team discovered during a routine inspection of new malware samples submitted to VirusTotal. It encrypts files on compromised systems, replaces original filenames with randomly generated strings, and appends a shared random extension. The ...
Published: August 02, 2026 Category: Removal guides
19. Golden Woolf Ransomware
What kind of malware is Golden Woolf?
Golden Woolf is ransomware our researchers discovered while inspecting new malware samples submitted to VirusTotal. It encrypts files on the victim's computer, appends the .wolf extension to filenames, and opens a pop-up window with ransom demands.
On our test ...
Published: July 29, 2026 Category: Removal guides
20. CRIMSON Ransomware
What kind of malware is CRIMSON?
CRIMSON is ransomware discovered by our researchers during a routine inspection of new submissions to the VirusTotal website. It encrypts victims' files and demands payment in exchange for decryption. After completing encryption, the ransomware presents its ransom demands ...
Published: July 26, 2026 Category: Removal guides
21. KansasGroup Ransomware
What kind of malware is KansasGroup?
KansasGroup is ransomware our research team identified while analyzing new file submissions on VirusTotal. Like most ransomware, it encrypts files on the infected machine and demands payment in exchange for decryption.
On our test machine, this ransomware appended ...
Published: July 26, 2026 Category: Removal guides
22. Own Ransomware
What kind of malware is Own Ransomware?
Own Ransomware is a ransomware-type program discovered by our researchers during a routine inspection of new submissions to the VirusTotal website. It encrypts files on the infected device and demands payment in exchange for decryption.
On our test machine, ...
Published: July 26, 2026 Category: Removal guides
23. Devill Ransomware
What kind of malware is Devill Ransomware?
Devill is ransomware that we discovered while examining new file submissions to the VirusTotal website. It encrypts files, appends a randomly generated five-character extension to their filenames, changes the desktop wallpaper, and creates a text-file ransom ...
Published: July 26, 2026 Category: Removal guides
24. InterServer Ransomware
What kind of malware is InterServer?
InterServer is ransomware our research team identified during a routine inspection of samples submitted to VirusTotal. It encrypts files, appends a variant-specific extension (e.g., .interserver12), and creates an HTML ransom note named RANSOM_NOTE.html. The attackers ...
Published: July 23, 2026 Category: Removal guides
25. NoMatter Ransomware
What kind of malware is NoMatter?
NoMatter is ransomware discovered by our researchers during a routine inspection of new submissions to VirusTotal. It encrypts victims' files, changes the desktop wallpaper, and drops a ransom note in a text file named README.txt. Unlike most ransomware, NoMatter does ...
Published: July 23, 2026 Category: Removal guides
26. BlackWizard Ransomware
What kind of malware is BlackWizard?
BlackWizard is ransomware that our researchers discovered during a routine inspection of new file submissions to VirusTotal. It encrypts victims' files and demands payment in exchange for a decryption key. The group behind it identifies themselves as "Ransomware ...
Published: July 23, 2026 Category: Removal guides
27. FadeSEC Ransomware
What kind of malware is FadeSEC?
FadeSEC is ransomware our research team discovered while examining malware samples submitted to VirusTotal. It encrypts victims' files and displays an interactive full-screen ransom message. Notably, restarting or re-logging into the system dismisses the screen lock, ...
Published: July 21, 2026 Category: Removal guides
28. BLACKNET Ransomware
What kind of malware is BLACKNET ransomware?
BLACKNET is ransomware that we discovered while examining malware samples submitted to VirusTotal. It encrypts files on the victim's device, replaces the desktop wallpaper with a ransom message, and delivers additional demands through a pop-up window and ...
Published: July 15, 2026 Category: Removal guides
29. HYFLOCK Ransomware
What kind of malware is HYFLOCK?
HYFLOCK is ransomware that we discovered while examining malware samples submitted to the VirusTotal platform. Like other ransomware, it encrypts files on the victim's computer, making them inaccessible, and demands payment in exchange for decryption.
On our test ...
Published: July 08, 2026 Category: Removal guides
30. SUCKS 2 SUCK Ransomware
What kind of malware is SUCKS 2 SUCK Ransomware?
SUCKS 2 SUCK is ransomware discovered by our researchers during a routine inspection of new submissions to the VirusTotal website. Once it infects a system, it encrypts files, appends the .encrypted extension to their filenames, and covers the screen ...