We just released a new decryption tool for the Muhstik ransomware strain. You can download the FREE decryption tool linked below. A detailed guide is also included.
Muhstik is a strain of ransomware that encrypts files on compromised QNAP systems using AES-256, and adds the extension “.muhstik” to files.
The ransom note “README_FOR_DECRYPT.txt” contains the following text:
All your files have been encrypted.
You can find the steps to decrypt them in any the following links: http://126.96.36.199/.unlock/payment/[redacted ID] Could go offline at any time http://188.8.131.52/.unlock/payment/[redacted ID] Could go offline at any time
Or use TOR link, guaranteed Online 100% of the time: http://5mngytmdpeyyp6xk.onion/payment/[redacted ID] Use TOR browser to access .onion websites. https://duckduckgo.com/html?q=tor+browser+how+to
Do NOT remove this file and DO NOT remove last line in this file!
Your ID: [redacted ID]
Protect your device with Emsisoft Anti-Malware.Did your antivirus let you down? We won’t. Download your free trial of Emsisoft Anti-Malware and see for yourself. Start free trial
Regardless of what the ransom note might say, our decryption tool can help you recover your files for free. Please get in touch with our support team if you have any questions.