notes/info.txt
Location: RootDiscs, Desktop
G-STARS is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on August 1, 2023, this ransomware has been actively targeting systems worldwide.
G-STARS updates file modification timestamps after encryption.
G-STARS modifies encrypted files using specific patterns to mark them as encrypted:
After encrypting files, G-STARS displays ransom notes demanding payment for file recovery:
notes/info.txt
Location: RootDiscs, Desktop
notes/info.hta
Location: RootDiscs, Desktop
The following executable files are associated with G-STARS ransomware:
This G-STARS ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery, helping organizations defend against and recover from ransomware attacks like G-STARS.
The Hunt Engine uses Deep File Inspection to identify G-STARS across live data, replicated data, and backups. If this family is in your environment, Elastio finds it before encryption completes. Run a hunt against your recovery points to confirm.