AI & TechCybersecurityNewswireTechnology

LockBit 3.0 Ransomware: .BS82tAHwp File Extension Guide

Originally published on: July 12, 2026
▼ Summary

– A Windows PC was infected with ransomware that encrypts files with the .BS82tAHwp extension and leaves a ransom note named BS82tAHwp_README.txt.
– The ransom note demands cryptocurrency payment and provides the contact email Simoneken@proton.me with a victim ID of ef9ed5de7def4ewJL.
– Attackers offer to decrypt one file up to 1 MB for free as proof of recovery, but warn against using third-party decryption tools.
– The victim has not paid the ransom, disconnected the infected machine, and preserved all encrypted files and the ransom note unchanged.
– ID Ransomware could not identify the ransomware, and the No More Ransom LockBit 3.0 decryption checker found no available decryption key for the victim’s ID.

A Windows PC has been hit with an unknown ransomware strain, leaving all files encrypted with the .BS82tAHwp extension. The victim reports that ID Ransomware failed to identify the specific variant, and the No More Ransom LockBit 3.0 Decryption ID Checker also returned no matching key. The ransom note, named BS82tAHwp_README.txt, instructs victims to contact Simoneken@proton.me with a unique victim ID and demands payment in cryptocurrency.

The note claims a security vulnerability allowed attackers to encrypt files while preserving the original file structure. It offers to decrypt one file (up to 1 MB) for free, excluding databases, as proof of recovery capability. However, the victim has not contacted the attackers, has not paid any ransom, and has kept the infected machine disconnected from the network with all encrypted files and the ransom note intact.

Key details include the victim ID ef9ed5de7def4ewJL and a warning against attempting self-decryption or using third-party decryption tools. The attackers emphasize that contacting them via email is the only path to discuss pricing and payment.

The victim is now asking the community whether this . BS82tAHwp extension or the email Simoneken@proton.me has been seen before. They suspect it could be a new variant of LockBit or CriptomanGizmo, but are open to any identification or guidance toward a possible decryptor. Encrypted sample files, the ransom note, and original versions of some files are available for analysis.

If you have encountered this extension or have information about this ransomware family, your input could be crucial. The victim is actively seeking help to identify the strain and find a recovery path without paying the ransom.

(Source: BleepingComputer)

Topics

ransomware infection 98% unknown ransomware variant 95% ransom note details 93% cryptocurrency payment 90% free decryption offer 88% victim id usage 86% lockbit variant suspicion 84% decryption key unavailable 82% infected machine isolation 80% evidence preservation 78%