Kangaroo ransomware encrypts your files and locks you out of Windows

Khushaar Tanveer avatar. By: Khushaar Tanveer
2 minute read

Home » Kangaroo ransomware encrypts your files and locks you out of Windows

We are all familiar with the  Fabiansomware, Esmeralda, and the Apocalypse ransomware. For those who are not, they are pieces of malicious code all constructed by singular a cybercriminal gang. And now, they have made a return and upped their game with another powerful bit of infection with the name ‘Kangaroo‘.

The Kangaroo ransomware is known to extort money from innocent victims. The approach used is an old yet an effective one. The ransomware has been affirmed to locks users out from their computer, making it inoperable in a bid to convince them to pay up. What makes this ransomware stand out from other crypto-malware variants is its fake legal notice.

Just like the DXXD ransomware, users have a notice thrown in their faces after they log in. Moreover, users are denied the privilege to start a Task Manager or access the Explorer.exe responsible for displaying the Windows UI. Then, users are given a ransom to regain access to their files and their personal space.

Though the screen locker can be disabled in Safe Mode or by pressing the ALT+F4 keys combination, for many casual computer users, this could prevent them from using their computer.

Kangaroo ransomware installation

The installation process of the ransomware is significantly different from other common approaches. Instead of mainstream exploit kits, cracks, compromised sites, or Trojans, Kangaroo ransomware is installed manually by hacking into RDP.

Developers use Remote Desktop to gain unauthorized access to a user’s computer and execute the infected file containing the ransomware. A screen is then shown that displays the victim’s unique ID and their encryption key.

By selecting copy and continue, users allow the ransomware to starting the encryption process of their personal data. The ransomware also appends the .crypted_file extension to an encrypted file’s name. After process completion, the ransomware shows a fake lock screen. It suggests that there is a critical problem with the computer and that the data was encrypted. It then provides instructions on how to contact the developer at kangarooencryption@mail.ru to restore the data.

How to remove the Kangaroo ScreenLocker

To regain access to their Windows desktop, users will need to disable the Kangaroo executable from running. To achieve this, the targeted user will need to boot the computer into Windows Safe Mode. Then, they will be granted access to their OS again. Once logged into Windows Safe Mode, they can run the msconfig.exe and disable the malware from running.

RELATED STORIES YOU NEED TO CHECK OUT:

Discussions

Next up

7 ways to fix Windows Error Recovery on laptops

John Waibochi avatar. By: John Waibochi
7 minute read

You can fix  Windows Error Recovery errors using these methods: Remove recently added hardware Run Windows Start Repair Boot into LKGC (Last Known Good Configuration) […]

Continue Reading

How to fix Unable to open serial port error message

Milan Stanojevic avatar. By: Milan Stanojevic
5 minute read

A serial port can be useful, but some users reported Unable to open serial port message on their PC. This can be a big problem, […]

Continue Reading

How to fix Operation on the printer is required error

Milan Stanojevic avatar. By: Milan Stanojevic
6 minute read

Most of us print documents frequently, but sometimes Operation on the printer is required message can appear and prevent you from printing. This can be […]

Continue Reading