Phobos Ransomware

Recovery & Decryption

Phobos Ransomware Recovery & Decryption

Are your files encrypted by Phobos Ransomware and you need data recovery from Phobos?

If yes, then it is a company-wide encryption. Learn more about the Phobos ransomware, its decryption, recovery, removal and statistics.

Our Ransomware data recovery experts can help your business recover your files fast.

All our Ransomware Decryption process is performed remotely and we can schedule a consultation call with your team to assess the damage done to your files.

How do I know if Phobos Ransomware has infected my infrastructure?

When your files are unable to open, your databases are not working any more and you get a notice demanding a ransom payment in order to unlock your files, then you are probably a victim of a ransomware attack.
Phobos Ransomware was firstly detected in October 2017, and its a new ransomware virus family that is related to Dharma Ransomware.

This ransomware strain uses AES 256-bit encryption, thus making it almost impossible to decrypt your files using a free decryptor tool.

But how can I be sure that Phobos Ransomware family is the one that encrypted my files?

These are the symptomps and indications that show you that you have been infected by Phobos Ransomware:

  • PHOBOS Ransomware leaves a ransomware note file called: Your Files are Encrypted.Txt on the Desktop of the infected machine but also sometimes in the Documents folder
  • Your File extensions change to a format like this: <original name>.id[<victim ID>-<version ID>][<attacker’s e-mail>].<added extention> for example[BAF3BBED-2822].[]
  • You suddenly notice that you have lost your desktop wallpaper
  • Your CPU showing 100% peak value even though no applications are running
  • Your computer is very slow
  • Your hard disk is constantly showing operation at 100% and is very slow
  • You cannot use your antivirus software or it is deactivated without any obvious reason
  • A lot of your applications cannot execute (including your SQL server cannot load the databases)

Antivirus Software recognize Phobos Family like this

  • Dr.Web: Trojan.Encoder.27737, Trojan.PWS.Banker1.30220, Trojan.Encoder.28637, Trojan.Encoder.28626, Trojan.Encoder.29362, Trojan.Encoder.31543
  • BitDefender: Trojan.GenericKD.31737610, Gen:Variant.Ulise.24543, Trojan.GenericKD.31838640, Gen:Variant.Ulise.36831, Gen:Variant.Ransom.Phobos.*, Gen:Variant.Ulise.39944, Gen:Variant.Graftor.651871, Trojan.Ransom.Phobos.F
  • ESET-NOD32:  Win32/Filecoder.Phobos, A Variant Of Win32/Kryptik.GOLH, A Variant Of Win32/Filecoder.Phobos.A, A Variant Of Win32/Filecoder.Phobos.B, A Variant Of Win32/Filecoder.Phobos.C
  • ALYac: Trojan.Ransom.Phobos
  • Ikarus: Trojan-Ransom.Phobos
  • Malwarebytes: Trojan.Crypt, Ransom.Phobos
  • Sophos AV: Troj/Phobos-B
  • Symantec: ML.Attribute.HighConfidence
  • VBA32: BScope.TrojanRansom.Blocker

Phobos Ransomware File Extentions

Phobos team is using is using the following extentions to encrypt files:

  • .actin, .Acton, .actor, .Acuna, .actin, .Acton, .actor, .Acuff, .Acuna, .acute, .adage, .Adair, .Adame,  .age, .angus,
  • .banhu, .banjo, .Banks, .Banta, .Barak, .barak, .bbc, .blend, .BORISHORSE, .bqux,
  • .Caleb, .Cales, .Caley, .calix, .Calle, .Calum, .Calvo, .CAPITAL, .com,
  • .DDoS, .deal, .deuce, .Dever, .devil, .Devoe, .Devon, .Devos, .dewar,
  • .eight, .eject, .eking, .Elbie, .elbow, .elder, .eject
  • .Frendi, .help, .HORSELIKER,
  • .KARLOS, .karma,
  • .mamba, .octopus,
  • .phobos, .phoenix, .PLUT,
  • .WALLET, .zax,

Phobos Ransomware Emails

Phobos Ransomware Note Example 1

All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail
Write this ID in the title of your message 000QQQ
If there is no response from our mail, you can install the Jabber client and write to us in support of
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files. 

Free decryption as guarantee
Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price. 
Also you can find other places to buy Bitcoins and beginners guide here:

Phobos Ransomware Note Example 2

!!! All your data is encrypted !!!
To decrypt them send email to this address:
If there is no response from our mail, you can install the Jabber client and write to us in support of

Phobos Ransomware Note Example 3

Sometimes ransomware operators do not leave any ransomware note.

In such cases the contact name of the operator is on the actual files.

When analysing the file names we can see that you can find a unique identifier for each encryption source plus the operator ID.

Its very important to enumerate all IDs when dealing with the ransomware attack.

An example is this:[BAF3BBED-2822].[].eight

How does the Ransomware infect the infrastructure

  • Remote Desktop Connection: 83%
  • Phishing Emails: 16%
  • Infrastructure Vulnerabilities: 3%

Generic Decryption Success Rates of Phobos Ransomware

Unfortunately Phobos Ransomware Operators in generic are one of the worst group when examining reliability.

Operators according to our experience do not have a good reputation in general.

  • Generic Success Rate of Phobos Ransomware Decryption: 82% (17% demand more ransom payment after first payment)
  • Some of them deliver vague instructions and victims can mess things up when running the decryptor.
  • Some others demand more payment for no obvuous reason than blackmailing you.

Also we have seen cases that the operators take your money and go away.

Some attackers have a good reputation for providing working Phobos decryptors. Others are known as scammers and will never provide a decryption tool.

Unfortunately, hackers will receive the ransom payment and get away with it, leaving the victim in cold waters.

Characteristics of Phobos Ransomware attacks

  • Operators of Phobos ransomware are targeting large organizations usually. That’s why Ransom Payments for Phobos are quite high.
  • The average Phobos Ransom request is usually between $5,000–$25,000. In addition, approximately 10% -15% of Bitcoin exchange fees are applied when using buy options such Wire transfer, Paypal or Credit card.

Average Length of Phobos Ransomware Incident Resolution

  • Without Tictaclabs Help: 13-17 days
  • With Tictaclabs Help: 3-7 days

My files are encrypted by Phobos, what should I do now?

First of all don’t panic, since we have many options to help you.

If you do not understand what a Ransomware Virus is, you should read our dedicated section on What is Ransomware.

Please read our instructions carefully:

  • Disconnect the infected computer from the network
  • Do not attempt any communication with the hackers
  • Take a full image backup of your system… yes it can be worse than just the encryption
  • Report the crime to your local Cyber Crimes Department
  • Phobos Ransomware, if left unattended, will try to encrypt all your infrastructure
  • Talk to our Ransomware Incident Response Team, because we have a very good chance to get your files 100% recovered faster than you can, and probably without any payment.