- Home
- Detectable Ransomware
- Wacatac
Ransomware Research
Wacatac Ransomware
Wacatac is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on November 1, 2019, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: DeathRansom.
Quick Facts
- Ransomware Family
- Wacatac
- First Seen
- November 1, 2019
- Known Aliases
- DeathRansom
How Wacatac Ransomware Works
Targeted Files
Markers 66ee3840a9722d3912b73e477d1a11fd0e5468769ba17e5e71873fd519e76def -> no ext.
File Encryption Patterns
Wacatac modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..wctc
..ADHUBLLKA
Ransom Note and Payment Demands
After encrypting files, Wacatac displays ransom notes demanding payment for file recovery:
read_me.txt
Ransom message:
notes/read_me.txt
Note locations:
EveryFolder
Technical Indicators
Associated Executable Files
The following executable files are associated with Wacatac ransomware:
SVGDGGQO.exe
A3D7DBGZ.exe
2p1km7pr6l.exe
f19bmb3o0e.exe
XFE1HD2S.exe
WH5WL68J.exe
death.exe
lsass.exe
ransomware
Elastio Can Help You
Don't let Wacatac ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This Wacatac ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Wacatac.
Last updated: July 30, 2025