- Home
 - Detectable Ransomware
 - KeRanger
 
Ransomware Research
KeRanger Ransomware
KeRanger is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on March 1, 2016, this ransomware has been actively targeting systems worldwide.
Quick Facts
- Ransomware Family
 - KeRanger
 - First Seen
 - March 1, 2016
 
How KeRanger Ransomware Works
File Encryption Patterns
KeRanger modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..encryptedRansom Note and Payment Demands
After encrypting files, KeRanger displays ransom notes demanding payment for file recovery:
README_FOR_DECRYPT.txtRansom message:
notes/README_FOR_DECRYPT.txt
Technical Indicators
Associated Executable Files
The following executable files are associated with KeRanger ransomware:
Transmission-2.90.dmg31b6adb633cff2a0f34cefd2a218097f3a9a8176c9363cc70fe41fe02af810b9_dmgKeRanger2.dmgTransmission-2.90-infected.dmg1d6297e2427f1d00a5b355d6d50809cb _Transmission-2.90.dmg_d1ac55Transmission-2.90.dmg.bin1d6297e2427f1d00a5b355d6d50809cb _Transmission-2.90.dmgTransmission-2.90.dmg_d1ac55A.dmgTransmission-2.90.dmg_1.dmgTransmission-2.90-2.dmgTransmission-2.90_1.dmgTransmission856b1d956112b0b7bd3e44f20cf1f2c19 _TransmissionKeRanger.3..Mach-O1_TransmissionGeneral.rtfkernel_service1.rtftest214a4df1df622562b3bf5bc9a94e6a783 _General.rtf_58c99fe20b348702b936abb0General.upx4.dmgTransmission-2.90-DO-NOT-touch.dmgTransmission-2.90.dmg_d7d765Transmission-2.901.dmgTransmission-2.90_d7d765.dmgTransmission-2.90_2.dmgTransmission-2.90.2dmg7test13151d9a085d14508fa9f10d48afc7016 _Transmission2_Transmission5.rtf861c3da2bbce6c09eda2709c8994f34c _General.rtf_General_.upx
Elastio Can Help You
Don't let KeRanger ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This KeRanger ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like KeRanger.
Last updated: October 30, 2025
Recent Ransomware
Explore other threats in our database