If a valid gift code link is entered, the ransomware will decrypt the files using an embedded static decryption key. The malware appends the “.givemenitro” extension to the filenames of the encrypted files.Īt the end of an encryption process, NitroRansomware will change the user’s wallpaper to an evil or angry Discord logo.Īccording to Lawrence, when a user enters a Nitro gift code URL, the ransomware will verify it using a Discord API URL. Unlike other types of ransomware attacks which demand thousands, if not millions, of dollars, NitroRansomware deviates from the norm by demanding a $9.99 Nitro Gift code instead.Īs per BleepingComputer’s analysis, upon executing the ransomware, it will encrypt the victim’s file and will give 3 hours to them to provide a valid Discord nitro. It actually checks if you entered a valid gift code.Īlthough Discord is a free VoIP, they offer a $9.99 per month Nitro subscription add-on that provides additional benefits, such as larger uploads, HD video streaming, enhanced emojis, and the ability to boost your favorite server. You have under 3 hours to give us Discord nitro.”
“There is no other way to open it unless you have the decryption key. There’s a ransomware called “Nitro Ransomware”. BleepingComputer owner Lawrence Abrams reported infections of new singular ransomware dubbed NitroRansomware which demands a Discord Nitro gift code to the victims to decrypt their files.