Telecrypt Ransomware

Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:30:55

Targeted regions: country_code:ru

Context

This is most likely to affect Russian speaking users, since the note is written in Russian. Therefore, residents of Russian speaking country are affected. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. The ransomware’s authors would request around $75 from their victims to provide them with a decryptor (payments are accepted via Russian payment services Qiwi or Yandex.Money ). Right from the start, however, researchers suggested that TeleCrypt was written by cybercriminals without advanced skills. Telecrypt will generate a random string to encrypt with that is between 10-20 length and only contain the letters vo,pr,bm,xu,zt,dq.

Reports & references

  • id-ransomware.blogspot.co.il — Telecrypt Ransomware (report)
  • securityweek.com — Telecrypt Ransomwares Encryption Cracked (report)
  • malwarebytes.app.box.com — Kkxwgzbpwe7Oh59Xqfwcz97Uk0Q05Kp3 (report)
  • blog.malwarebytes.com — Telecrypt The Ransomware Abusing Telegram Api Defeated (report)
  • Kaspersky — The First Cryptor To Exploit Telegram (report)

External references