FSociety targets Windows OS and its code is based on EDA2, an open-source ransomware project published in early 2016. Its ransom note image contains the logo of the fictional hacking group featured on the television show, Mr. Robot. Security researchers who discovered this variant noted that it seems to be in the early stages of development and it not being actively distributed as no ransom note text or contact information were found and it only currently targets a test folder on the Windows desktop. FSociety appends .locked to encrypted file names.
UPDATE 10/2/2016: A new version of the FSociety ransomware was discovered. It appends .email@example.com to encrypted file names and generates ransom notes named fs0ciety.html. Contact the security researchers on the Bleeping Computer forum here for help with this variant.
- Bleeping Computer provides more information about FSociety here.
- The NJCCIC is not currently aware of any decryption tools available for FSociety.