What is AgeLocker Ransomware

Whilst most ransomware developers focus on infecting Windows-based systems, AgeLocker targets Mac and Linux, instead. The ransomware positions itself as a business-oriented virus that spreads on corporative companies, however, attacks on regular users happen as well. This crypto-virus encrypts data from business users and corporate networks with X25519 (with ECDH curve), ChaChar20-Poly1305, HMAC-SHA256 algorithms and then demands a 1-7 BTC ransom to get the files back. The encryption process looks pretty similar to Windows, the only difference is using different extensions and file formats. AgeLocker applies its personal command prompt to run the encryption process. Files that have been impacted by AgeLocker get assigned with personalized extensions based on user’s names. It is impossible to identify which file was infected because of AgeLocker ciphers the original name and adds a random extension at the end. Some people reported that their files were added with the .sthd2 extension and the name of encrypted files starts with the age-encryption.org URL-address. Once all files get locked successfully, the virus sends a ransom note (security_audit_.eml) to the victim’s e-mail.

AgeLocker Ransomware
Hello ***,
Unfortunately a malware has infected your network and a millions of files has been encrypted using a hybrid encryption scheme.
File names encrypted too.
Encrypted hosts are:
1. ***
2. ***
3. ***
Mac + external drives
1. ***
2. ***
3. ***
You have to pay for decryption in Bitcoins.
The price depends on how fast you write us.
After payment we will send you the tool(for mac and linux) that will decrypt all your files.
Free decryption as guarantee
Before paying you can send us up to 5 files for free decryption.
The total size of files must be less than 4Mb (non archived), and files should not contain valuable information. (databases, backups, large excel sheets, etc.), file name shouldn't be changed.
How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
Also you can find other places to buy Bitcoins and beginners guide here:
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Note: we can answer up to 6-9 hours, because of another timezone.

In this note, it is recommended to not use third-parties decryptors and other tools. Instead, you should pay for the decryption software in BTC. If you do not do it fast enough, the price will be increased significantly. Also, extortionists allow victims to send up to 5 minor files (less than 4MB) that should not contain any valuable information. In practice, this is just a trick to boost up the trust of gullible users. Unfortunately, manual decryption is next to impossible. The only way to restore your data is uninstalling AgeLocker Ransomware and copying your files back from external and unplugged backups in case you made them preemptively. Our guide below will tell you removal instructions and essential tips upon being protected against such threats.

agelocker ransomware

How AgeLocker Ransomware infected your computer

Because AgeLocker is relatively fresh, experts have not got enough intel upon its distribution yet. For now, it is presumably spread via malicious attachments in e-mail messages, trojans, unprotected RDP configuration, fake software cracking tools, backdoors, keyloggers, and others. When it comes to e-mail spam, cybercriminals tend to inject malvertising files (e.g. MS Office documents, PDFs, executables, JavaScript files, etc.) and force inexperienced users into their opening. This, therefore, leads to the inevitable infection of malware like AgeLocker Ransomware, for instance. Unless you want to be part of the cyber-criminalistic world, you should take simple measures to stay protected against similar threats. We will shed some light on that in the article below.

  1. Download AgeLocker Ransomware Removal Tool
  2. Get decryption tool for your files
  3. Recover encrypted files with Stellar Data Recovery Professional
  4. Restore encrypted files with Windows Previous Versions
  5. Restore files with Shadow Explorer
  6. How to protect from threats like AgeLocker Ransomware

Download Removal Tool

Download SpyHunter for Mac

To remove AgeLocker Ransomware completely, we recommend you to use SpyHunter for Mac from EnigmaSoft Limited. It detects and removes all files, folders, and registry keys of AgeLocker Ransomware. The trial version of SpyHunter for Mac offers virus scan and 1-time removal for FREE.

Alternative Removal Tool

Download Spyhunter for Mac

To remove AgeLocker Ransomware completely, we recommend you to use CleanMyMac. It detects and removes all files, folders, and registry keys of AgeLocker Ransomware and prevents future infections by similar viruses.

AgeLocker Ransomware files:


AgeLocker Ransomware registry keys:

no information

How to decrypt and restore your files

Use automated decryptors

Download Trend Micro Ransomware Decryptor for macOS

trend micro ransomware decryptor for macos

Use following tool from Trend Micro called Ransomware Decryptor for macOS, that can decrypt your files. Download it here:

Download Decryptor for macOS

There is no purpose to pay the ransom because there is no guarantee you will receive the key, but you will put your bank credentials at risk.

Dr.Web Rescue Pack

Famous antivirus vendor Dr. Web provides free decryption service for the owners of its products: Dr.Web Security Space or Dr.Web Enterprise Security Suite. Other users can ask for help in the decryption of your files by uploading samples to Dr. Web Ransomware Decryption Service. Analyzing of files will be performed free of charge and if files are decryptable, all you need to do is purchase a 2-year license of Dr.Web Security Space worth $120 or less. Otherwise, you don’t have to pay.

If you are infected with AgeLocker Ransomware and removed it from your computer you can try to decrypt your files. Antivirus vendors and individuals create free decryptors for some crypto-lockers. To attempt to decrypt them manually you can do the following:

Use Stellar Data Recovery Professional to restore your files

stellar data recovery professional for mac

  1. Download Stellar Data Recovery Professional for Mac.
  2. Click Recover Data button.
  3. Select type of files you want to restore and click Next button.
  4. Choose location where you would like to restore files from and click Scan button.
  5. Preview found files, choose ones you will restore and click Recover.
Download Stellar Data Recovery Professional

Using Time Machine:

If the Time Machine on your Mac is set up and running, do the following to restore your files.

  1. Open Launchpad go to Other folder and choose Time Machine.
  2. Scroll through the history of backups on the right until you find lost files.
  3. Choose files you want to restore and click Restore button.

Using Terminal:

  1. Open Applications > Utilities > Terminal.app.
  2. In opened window type cd .Trash command and press Enter (Return).
  3. Type mv {filename} ../ and press Enter. Please note, {filename} stands for the name of the file you want to restore.

If you are using Dropbox:

  1. Login to the DropBox website and go to the folder that contains encrypted files.
  2. Right-click on the encrypted file and select Previous Versions.
  3. Select the version of the file you wish to restore and click on the Restore button.

How to protect computer from viruses, like AgeLocker Ransomware, in future

1. Get special anti-ransomware software

Use RansomWhere? App

ransomwhere? app

RansomWhere? is a small free utility for MacOS, that runs in the background and constantly monitors your system for the presence of processes that may encrypt your files. In case ransomware is detected, it shows you related alert and allows you to stop or block the malicious process immediately. RansomWhere?, if used properly, will save a major part of the data on your Mac. Download it below:

Download RansomWhere? App

2. Back up your files

idrive backup

As an additional way to save your files, we recommend online backup. Local storages, such as hard drives, SSDs, flash drives, or remote network storages can be instantly infected by the virus once plugged in or connected to. AgeLocker Ransomware uses some techniques to exploit this. One of the best services and programs for easy automatic online backup is iDrive. It has the most profitable terms and a simple interface. You can read more about iDrive cloud backup and storage here.

3. Do not open spam e-mails and protect your mailbox


Malicious attachments to spam or phishing e-mails are the most popular method of ransomware distribution. Using spam filters and creating anti-spam rules is good practice. One of the world leaders in anti-spam protection for Mac is SpamSieve. It works with Apple Mail and various third-party applications and provides a very high level of anti-spam protection. Download it here:

Download SpamSieve
Previous articleHow to remove B-ok.org
Next articleHow to remove KeRanger Ransomware and decrypt .encrypted files (Mac)