FANDOM


888 ransomware is a cryptovirus that appends files after encryption using a .888 file marker.

Payloads

888 ransomware as previous Dharma members delivers a window with step-by-step payment instructions and warnings like:

Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or 
you can become a victim of a scam.

This is a common feature as well as the FILES ENCRYPTED.txt file that gets added to every folder on the computer and reveals a brief message containing the following text:

all your data has been locked us
You want to return?
write email donald888@mail.fr

Once the infected file lands on your device and gets executed, the computer becomes infected with direct ransomware or trojans that spread around different threats.

Community content is available under CC-BY-SA unless otherwise noted.