Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Threat library

Ransomware family library

Profiles of the families we see most often in China plus the globally active ones: identification markers, encryption behavior, an honest recoverability assessment and what to do next. Identify the family first, then decide how to recover.

70 families matched

More common in China (endpoints / servers)17

The families we handle most in Chinese enterprise environments. They usually get in through RDP brute force, weak database credentials or an exposed edge device, and go straight for file servers and production databases.

Leak-site regulars worldwide15

International crews run as ransomware-as-a-service that keep a running victim list on their dark web leak site. Most steal data before encrypting, and virtualization platforms are a priority target.

Emerging or resurgent in recent months23

Families that have just appeared or come back after a quiet spell. Their samples and tooling are still changing quickly and public research is thin, so have a sample identified before you act.

Data theft only, no encryption5

Groups that steal data and threaten to publish it without encrypting anything. The files themselves may be intact; the risk is disclosure and compliance, so response focuses on attribution and scoping the exposure.

Mobile2

Screen-locking and extortion malware targeting Android and iOS, usually spread through third-party app stores, repackaged installers and SMS links.

Older families that still shape the ecosystem8

Operations that have disbanded, been disrupted by law enforcement or rebranded, yet whose leaked builders and source code are still reused. Historical samples keep causing infections today.

Decryptor status explained

  • Free decryptor available

    A free decryptor has been published by a security vendor or law enforcement. Matching samples can be decrypted directly, but the exact version still has to be confirmed.

  • Some versions decryptable

    Only certain versions or key batches can be decrypted, or unencrypted fragments left by intermittent encryption can be recovered. Each sample needs its own assessment.

  • No public decryptor

    No public decryptor exists today. Recovery relies on backups, snapshots, database repair and fragment reconstruction.

Identification & lookup tools

Ransomware identification tool

Enter an encrypted file extension, a ransom note filename or part of a contact address and we will match it against our family profiles.

Encrypted extension index

An alphabetical index of extensions, from .locked and .mallox to .beijing, mapped back to the ransomware family behind them.