Changes in the Tastylock Cryptomix Ransomware Variant
While the encryption methods stay the same in this variant, there have been some slight differences. The ransom note is still named
_HELP_INSTRUCTION.TXT, but now uses the
t_tasty@aol.com email for a victim to contact for payment information.
Tastylock CryptoMix Ransom Note
The next noticeable change is the extension appended to encrypted files. With this version, when a file is encrypted by the ransomware, it will modify the filename and then append the .tastylock extension to encrypted file's name. For example, a test file encrypted by this variant has an encrypted file name of
0D0A516824060636C21EC8BC280FEA12.tastylock.