A new variant of BTCWare ransomware was discovered by Michael Gillespie and uses the .[email]-id-id.shadow in encrypted files. This one mainly targets remote desktop services that are not sufficiently protected, allowing an attacker to install the ransomware manually.
Although not much has changed in terms of how it infiltrates (remote desktop, emails), the email address for the decryptor has changed to “paydayz@cock.li”. Also notable is the change in the suffix of the encrypted files, for example a file of the format “test.jpg” when encrypted will become “test.jpg.[paydaz@cock.li]=id=CoC.shadow”.
At present, there does not appear to be any known method for decrypting Shadow BTCware files. However, companies dealing with ransomware are reminding us of some basic protection measures.
- BACKUP is perhaps the most important thing that someone should do regularly on their computer. Clearly, it makes no sense to back up to the disk itself. Your data should be written to an external disk or USB stick which should be disconnected after you finish the process.
- Do not open attached files that you do not know who sent them.
- Do not open attached files if you are not sure the sender is the right one.
- Check the files with an online tool, e.g. (VirusTotal)
- Update the operating system as well as the various programs used.
- Have security software installed.
- Use difficult passwords - which you will definitely remember - and, if possible, different ones for each site you use.

