Most ransomware – malicious software that locks computer screens and then demands ransom – has been developed in Russia and Ukraine. However, Symantec experts have discovered an interesting Chinese version of the malware.
The Ransomlock variant analyzed by Symantec, containing Trojan.Ransomlock.AF, is developed in an easy-to-use programming language. It is mainly distributed via the popular IM application.
Once it infects a computer, the malware changes the current user’s Windows password to “tan123456789.” Additionally, it changes the account name to “contact [IM ACCOUNT USER ID] if you want to know the password.”
If the victim contacts the malware administrator, they will suggest paying 20 Chinese Yuan, around 3 euros, if they want the new password.
Symantec experts were able to determine the password because it was hardcoded within the malware code they analyzed. However, cybercriminals can change it at any time.

