  • The behavior of the Judge ransomware follows the well-known pattern of malware of this type. Judge starts by checking whether it runs in a sandbox or not, then terminates certain Windows processes and completely erases restore points to make it impossible for the user to recover data. After that, it proceeds to encrypting files on the victim’s computer.

    The AES-256 encryption algorithm is used for locking the target files and a new extension is appended to each, in the following form: “[[email protected]].judge”. As such, the files are rendered unusable. Every file is encrypted using the key and the IV generated by the ransomware.

    Users who are experiencing such symptoms on their computers will be glad to know that Tesorion released the Judge Decryptor, which can unlock non-corrupted files encrypted by the Judge ransomware without having to pay a dime to the attacker.

    The Judge Decryptor is extremely easy to use. In fact, the application comes with a set of complete instructions, allowing users to follow a few simple steps to get their files back. .

    The ransom note generated by the Judge ransomware is required to generate the decryption key. This file, called “info.txt”, should be found in any folder where an encrypted file is located. Next, the user will just have to wait for the decryption server to process their request. It might happen that the decryptor also requires an encrypted file in one of the following formats: DOCX, XLSX, PPTX or ZIP.

    Once the request is processed, the decryption can start. All that is left for you to do is select a folder where the unlocked files will be saved. By default, the decryptor selects the same folder where the original file is located.

    The decryption process can take a long time, depending on the number of files to process, especially since all the files in the subfolders are also processed.

    Judge Decryptor promises to unlock un-corrupted files affected by the Judge ransomware, providing a quick method to recover your files. However, it cannot guarantee 100% rate of success forever, since new variants of ransomware are often released.