- Home
- Detectable Ransomware
- AnteFrigus
Ransomware Research
AnteFrigus Ransomware
AnteFrigus is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on November 1, 2019, this ransomware has been actively targeting systems worldwide.
Quick Facts
- Ransomware Family
- AnteFrigus
- First Seen
- November 1, 2019
How AnteFrigus Ransomware Works
File Encryption Patterns
AnteFrigus modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
./\.[a-z]{4,6}$/
Ransom Note and Payment Demands
After encrypting files, AnteFrigus displays ransom notes demanding payment for file recovery:
/^[a-z]{4,6}-readme\.txt$/
Ransom message:
notes/qrja-readme.txt
Note locations:
EveryFolder
/^CLICK_HERE-[a-z]{4,6}\.txt$/
Ransom message:
notes/CLICK_HERE-eadfda.txt
Note locations:
EveryFolder
/^ATTENTION-[a-z]{4,6}-README\.txt$/
Ransom message:
notes/ATTENTION-daaefc-README.txt
Note locations:
EveryFolder
Technical Indicators
Associated Executable Files
The following executable files are associated with AnteFrigus ransomware:
Trojan.Ransom.AnteFrigus.exe
rad26628.tmp.exe
out
directx_update.exe
03-31_47.254.179.98_FEACCFFC7990693228933D5A5F67B833_DirectX_Update.exe
DirectX_Update.exe
DirectX_Update[1].exe
R7KIOWY5.exe
Elastio Can Help You
Don't let AnteFrigus ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This AnteFrigus ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like AnteFrigus.
Last updated: July 30, 2025