Kangaroo ransomware encrypts your files and locks you out of Windows

2 minute read

Home » News » Kangaroo ransomware encrypts your files and locks you out of Windows

We are all familiar with the  Fabiansomware, Esmeralda, and the Apocalypse ransomware. For those who are not, they are pieces of malicious code all constructed by singular a cybercriminal gang. And now, they have made a return and upped their game with another powerful bit of infection with the name ‘Kangaroo‘.

The Kangaroo ransomware is known to extort money from innocent victims. The approach used is an old yet an effective one. The ransomware has been affirmed to locks users out from their computer, making it inoperable in a bid to convince them to pay up. What makes this ransomware stand out from other crypto-malware variants is its fake legal notice.

Just like the DXXD ransomware, users have a notice thrown in their faces after they log in. Moreover, users are denied the privilege to start a Task Manager or access the Explorer.exe responsible for displaying the Windows UI. Then, users are given a ransom to regain access to their files and their personal space.

Though the screen locker can be disabled in Safe Mode or by pressing the ALT+F4 keys combination, for many casual computer users, this could prevent them from using their computer.

Kangaroo ransomware installation

The installation process of the ransomware is significantly different from other common approaches. Instead of mainstream exploit kits, cracks, compromised sites, or Trojans, Kangaroo ransomware is installed manually by hacking into RDP.

Developers use Remote Desktop to gain unauthorized access to a user’s computer and execute the infected file containing the ransomware. A screen is then shown that displays the victim’s unique ID and their encryption key.

By selecting copy and continue, users allow the ransomware to starting the encryption process of their personal data. The ransomware also appends the .crypted_file extension to an encrypted file’s name. After process completion, the ransomware shows a fake lock screen. It suggests that there is a critical problem with the computer and that the data was encrypted. It then provides instructions on how to contact the developer at kangarooencryption@mail.ru to restore the data.

How to remove the Kangaroo ScreenLocker

To regain access to their Windows desktop, users will need to disable the Kangaroo executable from running. To achieve this, the targeted user will need to boot the computer into Windows Safe Mode. Then, they will be granted access to their OS again. Once logged into Windows Safe Mode, they can run the msconfig.exe and disable the malware from running.

RELATED STORIES YOU NEED TO CHECK OUT:

Discussions

Next up

Nvidia GameStream not working with Windows 10 [FIX]

Alexandru Voiculescu By: Alexandru Voiculescu
2 minute read

Many users encountered a pretty severe issue with Nvidia. They couldn’t stream games in Windows 10. No matter what they tried, they didn’t manage to […]

Continue Reading

Best Windows 10 foldable laptops you can buy pretty soon

Tashreef Shareef avatar. By: Tashreef Shareef
3 minute read

The evolutions of portable computers aka laptops is staggering, to say the least. From fitting a large desktop power into your backpack (Dulmont Magnum) to […]

Continue Reading

Can’t open Power BI files? Use these solutions

John Taylor avatar. By: John Taylor
2 minute read

Power BI users have been frequently complaining about not being able to open their Power BI files at times. They have experienced error messages when trying […]

Continue Reading