Ransomware XIII

The XIII ransomware is a member of the Phobos ransomware family. Phobos was one of the most successful ransomware attacks of 2021.

Like the vast majority of ransomware groups, Phobos ceased its activities after a large spike in successful attacks. But what is becoming very common is the creation of families by these groups.

XIII ransomware invades victims’ devices through malicious e-mails, illicit programs, phishing campaigns and other ways.

In the process of encrypting the data, the extension”.XIII” is added to the files. After that, files are created with the terms for the ransom, called “info.txt” and “info.hta”.

In the ransom note the victims are threatened that if they do not pay the ransom the files will be completely lost, and that the ransom must be paid in cryptocurrencies.

Inside this ransom note are two e-mails “xlll@imap.cc” and “xlll2@xmap.cc”, containing the website address to pay to receive the decryption key.

Government authorities discourage paying the ransom, as these amounts fund the group for further attacks. Digital Recovery has therefore developed technologies capable of recovering data encrypted by ransomware without the need for the decryption key.

