Afrodita is a ransomware that runs on Microsoft Windows. It was discovered by S!Ri. It is part of the LockerGoga family. It is aimed at English-speaking users.



Afrodita is distributed through spam campaigns (emails). They send malicious MS Excel documents that are designed to install this ransomware. However, in order for that document to be able to install Afrodita it is required to give it a permission to enable macros commands/editing. Once it is done, this document starts installation of Afrodita.

It can also be distributed by hacking through an insecure RDP configuration, using deceptive downloads, botnets, exploits, malicious ads, web injects, fake updates, repackaged and infected installers.


It encrypts data with AES-256 and RSA-2048 encryption algorithms. Also, it creates a ransom note, the "__README_RECOVERY_.txt" text file which contains instructions on how to contact cyber criminals for information on how to pay a ransom (buy a decryption tool and key).

In order to prove that developers of Afrodita ransomware can help victims to decrypt their files they offer free decryption of one file. Victims can send it to them through Telegram (hxxps:// and, or email address. Cyber criminals behind this ransomware claim that to be able to recover the rest of encrypted files victims have to pay a ransom and wait for a decryption tool and/or key. According to them, it is the only way to get the files back. Unfortunately, that is true. Like many programs of this type, Afrodita encrypts files with a strong encryption algorithms that are impossible to 'crack'. In other words, the only way to decrypt files is by using the right decryption tool and/or key that only developers of this ransomware have. They claim that they can be trusted and it is not in their interest not do send decryption tools after a payment. The ransom note says the following:

