www.rivitmedia.comwww.rivitmedia.comwww.rivitmedia.com
  • Home
  • Tech News
    Tech NewsShow More
    Microsoft’s May 2025 Patch Tuesday: Five Actively Exploited Zero-Day Vulnerabilities Addressed
    7 Min Read
    Malicious Go Modules Unleash Disk-Wiping Chaos in Linux Supply Chain Attack
    4 Min Read
    Agentic AI: Transforming Cybersecurity in 2025
    3 Min Read
    Cybersecurity CEO Accused of Planting Malware in Hospital Systems: A Breach of Trust That Shocks the Industry
    6 Min Read
    Cloud Convenience, Criminal Opportunity: How Google Sites Became a Launchpad for Elite Phishing
    6 Min Read
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
    • Microsoft CVE Errors
  • How-To-Guides
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
  • FREE SCAN
  • Cybersecurity for Business
Search
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2023 rivitMedia.com. All Rights Reserved.
Reading: BlackHeart Ransomware
Share
Notification Show More
Font ResizerAa
www.rivitmedia.comwww.rivitmedia.com
Font ResizerAa
  • Online Scams
  • Tech News
  • Cyber Threats
  • Mac Malware
  • Cybersecurity for Business
  • FREE SCAN
Search
  • Home
  • Tech News
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
  • How-To-Guides
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
    • Cybersecurity for Business
  • FREE SCAN
  • Sitemap
Follow US
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
www.rivitmedia.com > Blog > Cyber Threats > Malware > BlackHeart Ransomware
MalwareRansomware

BlackHeart Ransomware

BlackHeart Ransomware: A Comprehensive Overview and Removal Guide

riviTMedia Research
Last updated: February 27, 2025 10:43 pm
riviTMedia Research
Share
BlackHeart Ransomware: A Comprehensive Overview and Removal Guide
SHARE

BlackHeart is a dangerous ransomware that belongs to the MedusaLocker family. Upon infection, BlackHeart encrypts files and appends the “.blackheart138” extension, making them inaccessible to the victim. This type of ransomware is designed to extort money from individuals or organizations by encrypting their valuable data and demanding a ransom in exchange for the decryption key. The threat is typically delivered through malicious email attachments, compromised websites, or infected software downloads.

Contents
Threat SummaryBlackHeart RansomwareWhat Is BlackHeart Ransomware?BlackHeart Ransom Note - Full TextSymptoms of BlackHeart Ransomware InfectionKey SymptomsHow BlackHeart Ransomware Is DeliveredHow to Remove BlackHeart Ransomware with SpyHunterBlackHeart RansomwarePreventive Measures Against BlackHeart and Other RansomwareConclusionBlackHeart Ransomware

Threat Summary

AttributeDetails
Threat NameBlackHeart ransomware
Threat TypeRansomware, Crypto Virus, File Locker
Encrypted Files Extension.blackheart138
Ransom Note File Nameread_this_to_decrypt_files.html
Associated Email Addressessupport1@contonta.com, support2@cavopo.com
Detection NamesAvast (Win64:RansomX-gen), ESET-NOD32 (Variant of Win64/Filecoder.MedusaLocker.A), Kaspersky (HEUR: Trojan-Ransom.Win32.Generic), Microsoft (Ransom: Win64/MedusaLocker)
Symptoms of InfectionFiles cannot be opened, files renamed with “.blackheart138” extension, ransom note displayed
DamageAll files encrypted, no access without paying ransom, possible installation of additional malware
Distribution MethodsMalicious email attachments, compromised websites, torrent websites, infected USB drives, malicious ads
Danger LevelHigh, due to encryption of important files and potential data leaks

Remove

BlackHeart Ransomware

With SpyHunter

Download SpyHunter 5
Download SpyHunter for Mac

What Is BlackHeart Ransomware?

BlackHeart ransomware is part of the MedusaLocker family, which is notorious for encrypting files and demanding a ransom from the victim to provide the decryption key. Upon execution, BlackHeart encrypts the victim's files, appending the ".blackheart138" extension to them. For example, "1.jpg" becomes "1.jpg.blackheart138," rendering the files inaccessible.

In addition to encrypting files, BlackHeart drops a ransom note called "read_this_to_decrypt_files.html." This note outlines the ransom demand and provides instructions for the victim on how to make payment and recover their files.

BlackHeart Ransom Note - Full Text

The ransom note left by the BlackHeart ransomware threat reads:

Your personal ID:
-
/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\
All your important files have been encrypted!
Your files are safe! Only modified. (RSA+AES)
ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE
WILL PERMANENTLY CORRUPT IT.
DO NOT MODIFY ENCRYPTED FILES.
DO NOT RENAME ENCRYPTED FILES.
No software available on internet can help you. We are the only ones able to
solve your problem.
We gathered highly confidential/personal data. These data are currently stored on
a private server. This server will be immediately destroyed after your payment.
If you decide to not pay, we will release your data to public or re-seller.
So you can expect your data to be publicly available in the near future..
We only seek money and our goal is not to damage your reputation or prevent
your business from running.
You will can send us 2-3 non-important files and we will decrypt it for free
to prove we are able to give your files back.
Contact us for price and get decryption software.
email:
support1@contonta.com
support2@cavopo.com
* To contact us, create a new free email account on the site: protonmail.com
IF YOU DON'T CONTACT US WITHIN 72 HOURS, PRICE WILL BE HIGHER.
* Tor-chat to always be in touch:

As seen in the ransom note, the attackers demand payment in exchange for the decryption key. They also threaten to release sensitive data if the victim refuses to pay, adding an element of extortion to their demands.


Symptoms of BlackHeart Ransomware Infection

When BlackHeart infects a system, it encrypts files and changes their extensions to .blackheart138. This is one of the first signs that a system has been compromised. Victims will also notice that they can no longer access their files and may see the ransom note displayed on their desktop or in the file system.

Key Symptoms

  • Files become inaccessible with the new extension, such as "1.jpg.blackheart138".
  • A ransom note titled "read_this_to_decrypt_files.html" appears on the victim's desktop.
  • The ransomware may display a message demanding payment to unlock files.
  • Possible installation of additional malware such as password-stealing trojans or information theft tools.

How BlackHeart Ransomware Is Delivered

BlackHeart ransomware is commonly spread through various methods:

  1. Infected Email Attachments – Cybercriminals often send phishing emails with malicious attachments, such as Word documents or executable files, that contain the ransomware payload.
  2. Compromised Websites – Ransomware can be downloaded by visiting compromised or malicious websites that exploit vulnerabilities in outdated software.
  3. Malicious Ads and Torrent Sites – Users may unknowingly download BlackHeart from malicious ads or pirated software from torrent websites.
  4. Infected USB Drives – The ransomware can also spread through USB drives that are already infected.

How to Remove BlackHeart Ransomware with SpyHunter

Remove

BlackHeart Ransomware

With SpyHunter

Download SpyHunter 5
Download SpyHunter for Mac

To remove BlackHeart ransomware from your system, follow the steps below using SpyHunter, a reputable anti-malware tool:

  1. Download and Install SpyHunter: Once downloaded, install the program.
  2. Run a Full System Scan: Launch SpyHunter and select the "Full System Scan" option to scan for BlackHeart ransomware and other potential threats.
  3. Remove Detected Threats: Once the scan is complete, SpyHunter will display a list of all detected threats, including BlackHeart. Select "Remove" to eliminate the ransomware from your system.
  4. Restart Your Computer: After removing the ransomware, restart your computer to ensure all changes take effect.
  5. Backup Your Files: If you have backups of your files, you can restore them once your system is clean.
Download SpyHunter 5
Download SpyHunter for Mac

Preventive Measures Against BlackHeart and Other Ransomware

  1. Keep Software Up-to-Date: Regularly update your operating system and software to close vulnerabilities that cybercriminals may exploit.
  2. Use Reputable Security Software: Install and maintain reliable antivirus software like SpyHunter to protect against malware.
  3. Backup Your Data Regularly: Keep backups of your critical files in an external location or cloud storage to ensure data is recoverable in the event of an attack.
  4. Be Cautious with Email Attachments: Do not open attachments or click on links in unsolicited emails, especially from unknown senders.
  5. Avoid Malicious Websites and Ads: Do not visit untrusted websites, and avoid clicking on pop-ups or ads that may contain malware.
  6. Disable Macros in Office Documents: Many ransomware infections are spread through malicious macros embedded in documents. Disable macros unless absolutely necessary.
  7. Use Strong Passwords and Multi-Factor Authentication: Secure your devices with strong passwords and enable multi-factor authentication wherever possible to prevent unauthorized access.

Conclusion

BlackHeart ransomware is a serious threat that can cause significant damage to individuals and organizations by encrypting valuable files and demanding a ransom for their release. It is crucial to follow the recommended steps for removing BlackHeart, using SpyHunter, and employing preventive methods to avoid falling victim to future ransomware attacks.

If you have been infected by BlackHeart, do not attempt to pay the ransom. Instead, focus on removing the ransomware from your system, restoring from backups if available, and implementing strong security measures going forward.

Remove

BlackHeart Ransomware

With SpyHunter

Download SpyHunter 5
Download SpyHunter for Mac

You Might Also Like

Sespaphizes.com Adware: An Overview
Gwrldtpnws3.xyz
Ads by quicksecuretest.com
Smartadsflow.top Ads
Webmail-Mail-Basic Email Scam: A Guide to Phishing Emails
TAGGED:.blackheart138 extensionBlackHeart ransomwarecrypto viruscyberattackCybersecuritydecryption softwareencrypted filesfile locker virusmalicious email attachmentsMedusaLocker Familyprevent ransomwareransom noteransomware attackransomware decryptionransomware guideRansomware preventionransomware protectionransomware recoveryransomware removalransomware removal guideSpyHunter

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Copy Link Print
Share
Previous Article XNXXporno.pro
Next Article QQ Ransomware
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Scan Your System for Free

✅ Free Scan Available 

✅ 13M Scans/Month

✅ Instant Detection

Download SpyHunter 5
Download SpyHunter for Mac

//

Check in Daily for the best technology and Cybersecurity based content on the internet.

Quick Link

  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

www.rivitmedia.comwww.rivitmedia.com
© 2023 • rivitmedia.com All Rights Reserved.
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US