- Home
 - Detectable Ransomware
 - Pay-or-Lost
 
Ransomware Research
Pay-or-Lost Ransomware
Pay-or-Lost is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on September 1, 2019, this ransomware has been actively targeting systems worldwide.
Quick Facts
- Ransomware Family
 - Pay-or-Lost
 - First Seen
 - September 1, 2019
 
How Pay-or-Lost Ransomware Works
File Encryption Patterns
Pay-or-Lost modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..kkkRansom Note and Payment Demands
After encrypting files, Pay-or-Lost displays ransom notes demanding payment for file recovery:
Ransom message:
notes/note.txt
Note locations:
OnceOnCompletionhythtyRansom message:
notes/hythty
Note locations:
DesktopTechnical Indicators
Associated Executable Files
The following executable files are associated with Pay-or-Lost ransomware:
$safeprojectname$.exePanduan_Kemaskini.doc
Elastio Can Help You
Don't let Pay-or-Lost ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This Pay-or-Lost ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Pay-or-Lost.
Last updated: October 30, 2025
Recent Ransomware
Explore other threats in our database