The Fiasko virus belongs under the Phobos ransomware family. Ransomware of this type encrypts all the data on your computer (photos, text files, excel sheets, audio files, videos, etc) and adds its extra extension to every file, creating the info.txt text files in every directory containing encrypted files.
Fiasko virus: what is known so far?
☝️ A strictly accurate description for the Fiasko is “a Phobos family ransomware infection”.
The renaming will be done by this pattern: id[xxxxxx].[contact-email].FIASKO. In the course of encryption, a file entitled, for instance, “report.docx” will be turned into “report.docx.id[9ECFA84E-3334].[[email protected]].FIASKO”.
In every folder containing the encrypted files, a info.txt file will be found. It is a ransom money note. Therein you can find information about the ways of paying the ransom and some other remarks. The ransom note usually contains a description of how to buy the decryption tool from the racketeers. You can obtain this decryptor after contacting [email protected] by email. That is basically the scheme of the felony.
Fiasko outline:
| Name | Fiasko Virus |
| Ransomware family1 | Phobos ransomware |
| Extension | .FIASKO |
| Ransomware note | info.txt |
| Contact | [email protected] |
| Detection | Win32/Injector.DDXX, MSIL/Filecoder.LokiLocker.D, MSIL/Grenam-A |
| Symptoms | Your files (photos, videos, documents) get a .FIASKO extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Fiasko virus |
The info.txt document coming in package with the Fiasko malware provides the following dispiriting information:
Hello! Can i Recover My Files? Sure. We guarantee that you can recover all of your files safely and easily! But You have to be fast!. How fast you will pay as fast all of your data will be back like before encryption. To contact us: Download the (Session) messenger (hxxtps://getsession.org) in messenger :\" 05301af0473d17cbabb6a4b8e4b39f5080b2e9be6454c0d040a1a2ddcf3ffe4355 \" You have to add this Id - and we will complete our converstion. In case of no answer in 24 hours write us to this e-mail:[email protected] You have to pay for decryption in Bitcoin ONLY! ATTENTION !!! Do not rename encrypted files, do not try to decrypt your data using third party software, it may permanent data loss. We have been in your network for a long time. We know everything about your company most of your information has already been downloaded to our server. We recommend you to do not waste your time if you dont wont we start 2nd part.
In the screenshot below, you can see what a folder with files encrypted by the Fiasko looks like. Each filename has the “.FIASKO” extension added to it.
How did Fiasko ransomware end up on my PC?
There is a huge number of possible ways of ransomware injection.
Nowadays, there are three most popular methods for criminals to have ransomware planted in your system. These are email spam, Trojan injection and peer-to-peer file transfer.
If you open your inbox and see letters that look like familiar notifications from utility services providers, postal agencies like FedEx, Internet providers, and whatnot, but whose “from” field is strange to you, be wary of opening those letters. They are very likely to have a viral item attached to them. Thus it is even riskier to open any attachments that come with emails like these.
As for the peer file transfer protocols like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. So you’d better be using trustworthy websites. Also, it is a good idea to scan the directory containing the downloaded items with the antivirus as soon as the downloading is complete.
How do I get rid of the Fiasko virus?
It is crucial to inform you that besides encrypting your files, the Fiasko virus will most likely install the Azorult Spyware on your PC to get access to credentials to different accounts (including cryptocurrency wallets). That program can extract your logins and passwords from your browser’s auto-filling data.
Sometimes racketeers would decrypt several of your files to prove that they do have the decryption program. As Fiasko virus is a relatively new ransomware, anti-malware developers have not yet found a method to undo its work. However, the decoding instruments are frequently updated, so the effective countermeasure may soon be available.
Understandably, if the hackers succeed in encoding victim’s critical data, the desperate person will probably comply with their demands. Despite that, paying to racketeers does not necessarily mean that you’re getting your blocked information back. It is still dangerous. After getting the ransom, the racketeers may deliver a wrong decryption key to the victim. There were reports about ransomware developers just vanishing after getting the money without even bothering to reply.
The optimal countermeasure to ransomware is to have aan OS restore point or the copies of your critical files in the cloud storage or at least on an external drive. Of course, that might be insufficient. The most important thing could be that file you were working on when it all happened. Nevertheless, it is something. It is also reasonable to scan your PC for viruses with the anti-malware utility after the system is rolled back.
There are other ransomware products, besides Fiasko, that work similarly. For instance, Hkgt, Lltt, Llqq, and some others. The two main differences between them and the Fiasko are the ransom amount and the encoding method. The rest is the same: documents become blocked, their extensions changed, ransom notes are found in each folder containing encrypted files.
Some fortunate people were able to decrypt the arrested files with the help of the free software provided by anti-ransomware developers. Sometimes the hackers mistakenly send the decoding code to the wronged in the ransom readme. Such an extraordinary fail allows the victim to restore the files. But of course, one should never expect such a chance. Make no mistake, ransomware is a criminals’ technology to lay their hands on the money of their victims.
How сan I avoid ransomware infiltration?
Fiasko ransomware doesn’t have a superpower, so as any similar malware.
You can protect your PC from ransomware injection within three easy steps:
- Ignore any letters from unknown senders with unknown addresses, or with content that has nothing to do with something you are waiting for (how can you win in a lottery without even taking part in it?). If the email subject is more or less something you are waiting for, check all elements of the questionable email carefully. A fake email will always contain a mistake.
- Avoid using cracked or unknown software. Trojans are often distributed as a part of cracked software, most likely as a “patch” to prevent the license check. But potentially dangerous programs are very hard to tell from trustworthy ones, as trojans may also have the functionality you need. Try to find information on this software product on the anti-malware message boards, but the best way is not to use such software.
Reasons why I would recommend GridinSoft3
Download Removal Tool.
Run the setup file.
Press “Install” button.
Once installed, Anti-Malware will automatically run.
Wait for the Anti-Malware scan to complete.
Click on “Clean Now”.
FAQ
🤔 Are the “.FIASKO” files accessible?
Negative. That is why ransomware is so frustrating. Until you decode the “.FIASKO” files you will not be able to access them.
🤔 The encrypted files are very important to me. How can I decrypt them quickly?
If the “.FIASKO” files contain some really important information, then you probably have them backed up. Otherwise, you might try to employ System Restore. The only question is whether you have saved any Restore Points that would be helpful now. The rest of the methods require patience.
🤔 What should I do if the Fiasko ransomware has blocked my computer and I can’t get the activation key.
🤔 What can I do right now?
Many of the blocked files might still be within your reach
- If you sent or received your important files through email, you could still download them from your online mailbox.
- You may have shared images or videos with your friends or relatives. Just ask them to post those images back to you.
- If you have initially downloaded any of your files from the Web, you can try doing it again.
- Your messengers, social media pages, and cloud disks might have all those files as well.
- It might be that you still have the needed files on your old computer, a laptop, phone, external storage, etc.
HINT: You can employ file recovery programs5 to retrieve your lost information since ransomware encodes the copies of your files, removing the authentic ones. In the tutorial below, you can learn how to use PhotoRec for such a restoration, but be advised: you can do it only after you remove the ransomware itself with an antivirus program.
Also, you can contact the following governmental fraud and scam sites to report this attack:
- In the United States: On Guard Online;
- In Canada: Canadian Anti-Fraud Centre;
- In the United Kingdom: Action Fraud;
- In Australia: SCAMwatch;
- In New Zealand: Consumer Affairs Scams;
- In France: Agence nationale de la sécurité des systèmes d’information;
- In Germany: Bundesamt für Sicherheit in der Informationstechnik;
- In Ireland: An Garda Síochána;
To report the attack, you can contact local executive boards. For instance, if you live in USA, you can have a talk with FBI Local field office, IC3 or Secret Service.

Leave a Comment