Share on facebookFacebook
Share on twitterTwitter
The Xot5ik ransomware is a variant of the Thanos ransomware, which has been responsible for numerous attacks, Europe has been the target of most attacks.
As usual for large ransomware groups, after numerous successful attacks they cease their activities because their attacks attract the attention of the authorities.
But after some time, the group reappears under a new name and with a new outfit, even though the main characteristics of the malware remain the same.
This is used as a distraction, the ransomware groups have found a goldmine with their attacks, they will hardly give up doing them.
Xot5ik ransomware invades devices through spam emails, cracked software download sites, and more.
Xot5ik uses RSA and AES encryption algorithm, which are the most used types in all ransomware.
After encrypting all files, a text file called “Инструкция.txt” is created, it is fixed on the desktop, in it is the terms for paying the ransom.
All encrypted files are given the extension .xot5ik, making it impossible for the user to access them.
The decryption key is kept in a remote server controlled by the criminals. The ransom is paid in cryptocurrencies.
There is no guarantee that the key will be released after the ransom is paid; the victim has to rely solely on the word of the criminals.
Digital Recovery specializes in the recovery of data encrypted by ransomware on HDDs, SSDs, Databases, Virtual Machines, Servers, Storages (NAS, DAS, SAN), RAID systems and others.
Our solutions are exclusive and were developed based on the General Data Protection Regulation (GDPR) so that there is full security for both parties.
We provide to all our customers the confidentiality agreement (NDA), all information about the process is confidential.
We are used to acting in the complex scenarios of data loss and, we have developed technologies so that the recovery is made in the fastest way possible, such as remote recovery and emergency mode recovery.
We don’t negotiate with hackers, we can recover files even without the decryption key. Contact us and start recovery now.