Service
Ransomware Decryption
- Identify the family first, then commit to a recoverable scope — without paying a ransom.
For organizations whose servers, databases or virtualization platforms have been encrypted: family identification, recoverability assessment and multi-path data extraction, with no ransom payment.
What this service covers
This service is for organizations that are already encrypted and whose operations have stopped. The goal is to recover as much core production data as possible without paying the attacker, and to shorten downtime.
What we do
- Family and version identification, based on the appended extension, the ransom note text, contact patterns inside the note, file header and footer structure, and the distribution of encrypted blocks. This step determines every path that follows, and it cannot be skipped.
- Recoverability assessment, performed on read-only images or copies: encryption algorithm and key handling, whether intermittent encryption was used, whether shadow copies or storage snapshots survive, and whether backups are usable. The output is an explicit recoverable scope.
- Decryption and repair. Where an official or vendor-published decryptor exists for the specific variant, we use it first. For databases and virtual disks we combine structure repair, page- and block-level repair, log replay, and extraction of unencrypted regions.
- Verification and handover: file integrity checks, database consistency checks and business sampling, delivered together with a verification checklist before anything goes back into production.
The limits, stated honestly
Whether data can be decrypted depends on the family and version, not on how much is paid or how hard anyone works. For mainstream strong-encryption families there is no feasible brute-force path unless keys have leaked, so any claim of "guaranteed decryption" or "100% recovery" is false.
When direct decryption is not viable we move to other paths — backup and snapshot restoration, file-level database repair, extraction of unencrypted remnants and fragments, and reassembly of valid data from intermittently encrypted files — and we state the expected outcome, cost and risk of each. If the assessment concludes the data is unrecoverable, we say so and advise on rebuilding instead of spending the client's time window on an uncertain approach.
Deliverables
- Family and variant identification, with the evidence and sample analysis behind it
- Recoverability assessment report: recoverable scope, available paths, expected outcome and risks
- Decryption and repair plan, with recovery priorities and downtime windows
- Post-recovery verification checklist: file integrity, database consistency, business sampling
- Operation log of the engagement plus a follow-up hardening checklist
How it works
Intake and containment guidance
We respond quickly after intake, establish the affected scope by phone or remote session, and immediately issue containment steps: isolate affected hosts from the network, do not reboot, do not reformat, do not reinstall, preserve the original ransom note, and pause automated jobs or backup runs that could overwrite data.
Sample collection and family identification
The client provides the ransom note and two or three encrypted samples — ordinary files with no sensitive content are enough. From these we determine family and version, and state whether a public decryptor exists for that build, whether intermittent encryption was used, and whether shadow copies are typically destroyed.
Recoverability assessment and sign-off
On read-only copies we assess the current state: how much of the data is encrypted, whether database files are repairable, what backups or snapshots survive, and which directories were untouched. The output is a recoverability assessment with tiered options, a quote and a time estimate — work starts only after the client signs off.
Decryption and data extraction
All work happens on copies while the original disks stay read-only, so nothing is damaged twice. Execution follows business priority: the databases and key files needed by core production systems first, archives and historical data after. Progress and the actually achieved ratio are reported at regular checkpoints.
Verification, handover and review
Before handover we complete integrity and consistency checks; databases must mount cleanly and pass sampled queries. We deliver the verification checklist and the operation log, and advise on the intrusion entry point — with optional handover to our forensics and hardening services.
When to use it
- File servers and shared drives encrypted; office and production documents will not open
- SQL Server, Oracle or MySQL data files encrypted and the application cannot start
- ESXi or Hyper-V virtual disks encrypted, taking several business systems down at once
- Backups deleted, or the backup server encrypted along with everything else
- A ransom note has arrived and you need an independent recoverability opinion before deciding
- A self-service decryptor from the internet was already tried and failed
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
Database Encrypted by Ransomware
When database files are encrypted, every business system that depends on them stops at once. This page explains how we triage an encrypted database, how recoverability is assessed, and when file repair, backup-plus-log restore, or rebuild is the right path.
SQL Server Database Encrypted by Ransomware
When SQL Server .mdf / .ldf files are encrypted, the ERP and inventory systems built on them — Yonyou U8, Kingdee K/3, Guanjiapo, Suda — stop completely. This page covers evidence handling, how we judge whether page-level repair is viable, and the conditions for backup-plus-log restore.
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Related ransomware families
- Some versions decryptable
LockBit
LockBit is one of the largest ransomware-as-a-service operations in the world. Despite the 2024 law-enforcement takedown it returned as LockBit 5.0, with working Windows, Linux and VMware ESXi payloads, and it remains one of the most frequently seen families in China.
- Free decryptor available
Phobos
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
- Some versions decryptable
Mallox
Mallox (also known as TargetCompany) breaks in mainly through brute-forced MS SQL Server credentials, targets database servers specifically, and has a Linux/ESXi variant. Files encrypted between 2023 and early 2024 may be decryptable with Avast's free tool; later builds have no public decryption method.
- No public decryptor
TellYouThePass
TellYouThePass is the archetypal vulnerability-driven ransomware family in China, mass-deployed against internet-facing ERP, OA, finance and middleware systems. It appends .locked and hits both Windows and Linux servers. No public decryptor exists.
- Some versions decryptable
GlobeImposter
GlobeImposter has been active since 2017 and is highly prevalent in China through its Chinese-zodiac variants (such as .Dragon4444) and Olympian-gods variants (such as .Ares666). It spreads by brute-forcing RDP/SMB and moving laterally, and caused widespread hospital infections in China in 2018. Mainstream variants have no decryptor.
Related questions
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- Recovery
Can files encrypted by ransomware be recovered?
Often in part, sometimes almost entirely, but nobody can promise it before seeing samples. Recoverability comes down to four things: the family and version (is there a public decryptor, seized keys or a known flaw), how the files were encrypted (in full, or only partly), which backups, snapshots and other copies survived, and what has been written to the disks since. Where a modern family encrypted files correctly and completely, no copies survive and the remnants have been overwritten, the data may genuinely be gone. Stop all writes and identify the family first.
- First response
What should we do when a server is hit by ransomware?
Isolate first and do not reboot: cut the affected server off at the switch or in the cloud security group, but leave it running. Then snapshot or image the system and data disks, keep the ransom note and encrypted samples, and check read-only whether shadow copies, cloud snapshots and backups survived. If several servers are down, set a restore order by business dependency, and bring nothing back online until the entry point is closed and every credential has been changed. What can be recovered depends on the family, the encryption mode and the backups.
- Ransom & cost
How much does ransomware decryption cost, and how long does recovery take?
There is no fixed price and no fixed timeline. Cost and duration depend mainly on whether the family and version can be decrypted, how many hosts and how much data are affected, how hard database and virtual machine repair will be, whether work is remote or on site, and whether overnight parallel work is needed. We do not quote over the phone: we assess first, then issue a written quotation covering scope, deliverables and expected timing, and start once both sides confirm. An initial family read usually takes hours; a full recoverability assessment normally takes one to several business days.
- Ransom & cost
Should we pay the ransom after a ransomware attack?
We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.
- Recovery
Which ransomware decryption tools exist, and are downloaded ones safe to use?
Yes, but not many. Legitimate free decryptors come from the No More Ransom project, law enforcement agencies and the official channels of vendors such as Emsisoft, Avast, Kaspersky, Bitdefender and 360, and each usually works only for specific versions of a specific family. Programs circulating online as universal or dedicated decryptors are often malware or paid scams. Even with a genuine tool, confirm the family and version match first, and run it only on copies of your files.
- First response
My files all have a new extension and won't open - what should I do?
Do not rename or repair anything yet. If files of many types share the same unfamiliar appended extension (often with an ID and an email address), text, HTA or HTML notes have appeared in every folder and the wallpaper has changed, it is almost certainly ransomware. If only one file type fails, USB files turned into shortcuts, or names are garbled but content opens, a file association, USB worm or encoding problem is more likely. Until you know, disconnect the network, keep the machine on, and save a sample plus the note for identification.
- Systems & software
What should we do when Guanjiapo or Suda account sets are encrypted by ransomware?
Isolate the server holding the account sets from the network but keep it powered on. Do not reinstall the accounting software, restore an account set over the original disk, or run decryptors from the internet. Guanjiapo, Suda, Chanjet T+ and T3, Kingdee KIS Professional and similar products mostly keep account sets in SQL Server, with built-in automatic backups on the same machine, so both tend to be encrypted together. How much comes back depends on the family and how it encrypted, whether a clean backup exists beyond that server, and whether the database files were only partly encrypted. After recovery, reconcile stock, receivables and payables line by line, and close the entry point before going back online.
FAQ
Frequently asked questions
Can you guarantee successful decryption?
No — and neither can anyone else. Whether decryption is possible is decided by the family and version: a small number of families have usable public decryptors because keys leaked or the implementation was flawed, while most mainstream families offer no feasible path unless keys are exposed.
Our approach is to run the recoverability assessment first and state plainly what can be recovered, to what degree, and by which path, so you can decide whether to proceed. Treat any vendor promising "100% decryption" as a red flag.
How long does the whole process take?
Family identification and a first read are usually a matter of hours. A full recoverability assessment depends on data volume and environment complexity, and normally concludes within one to several business days.
Execution varies far more: a single file server may take a day or two, while multiple virtual machines, large databases or file-by-file repair take considerably longer. The assessment report gives a staged time range, and we update it against real progress during execution.
Do we have to ship servers or disks to you?
Usually not. We work remotely on a 24/7 basis through remote sessions and controlled access channels, which covers clients anywhere in China.
On-site engineers are arranged when physical media are damaged, RAID structures are inconsistent, the environment does not permit remote access, or the client wants forensics performed in person. Whether an on-site visit is needed is settled during assessment.
Why do you advise against paying the ransom?
First, receiving a decryptor is not the same as getting data back: decryptors are often incomplete, extremely slow, or corrupt large files such as databases — and sometimes never arrive. Second, paying marks the organization as a payer, and repeat extortion is common. Third, moving such funds carries its own compliance exposure.
We do not pay ransoms, do not negotiate on a client's behalf, and do not handle ransom transfers. Spending the same budget on assessment, recovery and hardening is the better long-term trade.
The system was reinstalled or cleaned by antivirus — is there still a chance?
The odds drop, but they are not necessarily zero. Reinstalling overwrites the original data regions, and antivirus cleanup may remove key files, the ransom note and important logs along with the payload — all of which affect identification and some recovery paths.
Stop writing to that disk immediately, do not repartition, format or run disk checks, and keep the quarantined samples and quarantine records. We assess what remains in read-only mode first.
Updated