Colambia Ransomware
Summary
The files on the breached devices - documents, PDFs, archives, databases, images, and many more, will be encrypted with a strong cryptographic algorithm, leaving them in an unusable state. Restoration of the data without knowing the specific decryption key in possession of the attackers is typically impossible. More specifically, the threat appends .colambia to the original names of the processed files, followed by a specially generated ID string. The message makes it clear that the attackers are willing to assist with the restoration of the data only after being paid an unspecified ransom. To receive additional instructions, victims are directed towards messaging the two emails of the cybercriminals - royroy@cock.li and colambia@tutanota.com, or contacting them via qTOX chat.