- Name :- Kostya Virus
- Type :- Ransomware, Cryptovirus
- Short Description :- The ransomware will encrypt your files with an AES 256-bit encryption. Then it will display a ransom note with the name “Kostya” displayed on top.
- Symptoms :- The ransomware will display a ransom note written in Czech and lock files with the .k0stya extension appended to them.
- Distribution Method :- Spam Emails, Email Attachments
Kostya virus (also known as K0stia) is a Russian-named ransomware which hails from the same family as previously-released viruses Petya and Mischa. Though the real relationship between Kostya and the these viruses is not yet defined, we cannot turn down the possibility that this virus is yet another nasty work of the Russian hackers. It is interesting, though, that this Kostya is country-oriented and infects computers located in the Czech Republic. Its victims are asked to pay a ransom of 300 CZK which is equal to $12, so we must admit that this is one of the cheapest ransomware-type viruses.
However, no matter how much does it ask from its victims, it works like any other ransomware. According to PC experts, K0stia relies on AES-256 encryption key that it uses for encrypting its victims' files. As soon as it enters the system, it starts scanning computer’s hard disk and other locations for popular file extensions, such as .pdf, .jpg, .png, .mov, .avi, .pptx, .bmp, .doc, .docx and tens more. Good news is, that the virus only infects the C: drive, while D: partition usually remains untouched. Nevertheless, if you keep the most of your important documents on the C: drive, the consequences of this ransomware attack may be disastrous. It is especially important to remove Kostya virus from the infected device as soon as possible.
Readers recently started to report the following message being displayed when they boot their computer:
Co se stalo?Veškeré vaše soubory byly zašifrovány šifrovacím algoritmem AES-256 společně s vaším osobním počítačem.VAROVÁNÍ!!!Pokud nesplníte všechny dané požadavky uvedené níže do 12 HODIN , váš nynější dešifrovací klíč se SMAŽE a CENA STOUPNE NA 2000KČ!.PO 24 HODINÁCH SE VAŠE SOUBORY SMAŽOU A VY JE UŽ NIKDY NEUVIDÍTE!!![…]Jak vše odemknout? 300Kč.– Stačí zakoupit kartu PaySafe Card v hodnotě 300Kč ,zadat její kód(číslo) do textového pole pod tímto textem a stisknout tlačítko.Vaše platba pak bude odeslána k ověření. Po ověření budou vaše soubory a váš počítač uvedeny do původního stavu-Kde koupím PaySafe Card ?PaySafe Card se dá zakoupit v jakékoliv trafice, či pumpě. Stačí se zeptat prodejce.