WARLOCK DARK ARMY Ransomware
Summary
The goal of the cybercriminals behind the WARLOCK DARK ARMY Ransomware threat is to lock the data of their victims and then extort them for money, in the form of a ransom payment. The vast majority of ransomware attack operations follow this pattern - once activated on the breached devices, they will target the data of the victims and encrypt it with an uncrackable cryptographic algorithm. A new text file named read_it.txt will be created on the device, as a way to deliver a ransom note with instructions from the cybercriminals. Victims are expected to contact the hackers Telegram account at @WARLOCK_MAK to receive the specific crypto-wallet wallet to which the money is supposed to be transmitted. The full text of the ransom note is: All of your files have been encrypted by WARLOCK DARK ARMY Your computer was infected with a ransomware virus.