Heimdall Ransomware Data Recovery

Written byHeloise Montini
Heloise Montini

Heloise Montini is a content writer whose background in journalism make her an asset when researching and writing tech content. Also, her personal aspirations in creative writing and PC gaming make her articles on data storage and data recovery accessible for a wide audience.

Edited byLaura Pompeu
Laura Pompeu

With 10 years of experience in journalism, SEO & digital marketing, Laura Pompeu uses her skills and experience to manage (and sometimes write) content focused on technology and business strategies.

Co-written byBogdan Glushko
Bogdan Glushko

CEO at SalvageData Recovery, Bogdan Glushko has over 18 years of experience in high-security data recovery. Over the years, he's been able to help restore data after logical errors, physical failures, or even ransomware attacks, for individuals, businesses, and government agencies alike.

I think there's an issue with my storage device, but I'm not sure
Start a free evaluation

Heimdall is a new type of ransomware that is currently becoming more prevalent.

History

On May 22nd, 2017, Michael Gillespie discovered Heimdall Ransomware. Heimdall is a ransomware-as-a-service (RaaS) that is currently being distributed through various affiliate programs. Heimdall uses the EDA2 open source project for its encryption routine, which is why it is sometimes also referred to as EDA2 ransomware.

How does Heimdall work?

When this ransomware is executed, it will check to see if the computer is connected to the Internet. If an Internet connection is present, Heimdall will contact its Command & Control (C&C) server and send information about the infected computer. After generating a unique ID for the computer, Heimdall will create an RSA-2048 public/private key pair. Heimdall will use the public key to encrypt a file called “HELP_DECRYPT.txt”, which contains information on how to contact Heimdall’s developers for payment instructions. Heimdall will then scan the computer’s hard drive for certain file types and encrypt them using the AES-256 encryption algorithm. The AES-256 encrypted files will have the “.heimdall” extension appended to them.

What types of files does Heimdall Ransomware encrypt?

Heimdall Ransomware will search for and encrypt over 500 different types of files. A list of file extensions that Heimdall targets you find below:.3fr, .accdb, .ai, .arw, .bay, .cdr, .cer, .cr2, .crt, .crw, .dbf, .dcr, .der,.dfx, .dng, .doc, .docm, , docx,.erf,.indd,.jpe,.jpg,.kdc,.mdb,.mdf,.mef,.mkv,.mos,, mov,.mp3,.mp4,.mpeg,.mpg,.mrw,.nef,.nrw,.odb,.odc,.odm, .odp,.ods, .odt, .orf, .p12, .p7b, .p7c, .pdd, .pef, .pem, .pfx, .ppt, .pptm, .pptx, .PSD, .pst, .qbb, .qbm, .qbr, .qbw, .qbx, .qby, .qfx, .qwc, .raf, .rar, .raw, .rtf, .rw2, .rwl, .sr2, .srf, .srw, .wb2, .wpd, .wps, .xlk, .xls, .xlsm, .xlsx.This ransomware will also encrypt files on any connected network drives.

How much does Heimdall Ransomware cost?

The Heimdall developers currently charge between 0.5 and 1 Bitcoin (approximately $1,000-USD 2,000) for the Heimdall decryption key. Heimdall’s developers have stated that they will give a discount to victims who contact them within 72 hours of Heimdall Ransomware infection.Heimdall developers also offer a “free” decryptor that will decrypt three files for free. However, this “free” decryptor is only meant to show victims that Heimdall Ransomware is working and that Heimdall does indeed have the decryption key.

Protection

You can protect yourself from Heimdall and other ransomware infections by using a reliable anti-malware program and keeping your operating system and software up-to-date. You should also backup your important files regularly to minimize the risk of data loss in the event of a ransomware infection.

How to remove Heimdall Ransomware?

You can remove Heimdall Ransomware with a reputable anti-malware program. We recommend using Malwarebytes Anti-Malware, as it can detect and remove Heimdall and other types of malware from your computer. Once Heimdall has been removed, you can use a file recovery program to restore your encrypted files.

Is there a public decryption tool?

No, there is no public decryption tool for Heimdall Ransomware at this time.

You can only decrypt your files with the Heimdall decryption key, which is only available from Heimdall’s developers. We do not recommend paying the ransom, as there is no guarantee that Heimdall’s developers will provide you with the decryption key. Additionally, paying the ransom will only encourage Heimdall’s developers to continue their malicious activities.

Use a recovery software

We built SalvageData data recovery software to help you.

Contact a data recovery service

If you cannot remove Heimdall ransomware or access your files, you can try to restore them using a data recovery service.SalvageData Recovery ServicesOur Heimdall ransomware removal and file recovery services are designed to help you get your files back. We have a team of highly trained security experts who will work with you to get your files back. Contact us today for a free consultation.

Share this article

Related services

These are the most commonly requested data recovery services. At our headquarters' cleanroom lab, our certified engineers conduct a thorough review of any type of physical storage device, determining if there is logical or physical damage and carefully restoring all of the lost files.ces.

External Drive Data Recovery

We recover data from both external SSD and HDD drives. Rely on certified experts to restore your important files from damaged or corrupted external drives.

/services/data-recovery/external-drive/

Hard Drive Data Recovery

Recover data from all brands of HDD, PC hard drives, and hybrid disks. Our specialists ensure fast and secure recovery for any data loss scenario.

/services/data-recovery/hard-drive/

NAS Data Recovery

Recover data from NAS devices, including RAID configurations. Our team handles all types of NAS systems and ensures data recovery with minimal downtime.

/services/data-recovery/nas/

RAID Data Recovery

Our RAID data recovery services cover RAID 0, 1, 5, 10, and other configurations. We offer expert solutions for failed, degraded, or corrupted RAID arrays.

/services/data-recovery/raid/

SAN Data Recovery

Our team specializes in handling SAN devices from leading manufacturers like Dell EMC, HP, and IBM, ensuring efficient recovery with minimal disruption to your operations.

/services/data-recovery/san/

SD Card Data Recovery

Our recovery experts specialize in restoring data from SD and memory cards. We guarantee quick recovery with a no-data, no-charge policy.

/services/data-recovery/sd-card/

SSD Data Recovery

Our data recovery experts handle all SSD data loss scenarios with advanced tools, ensuring maximum recovery with high-security protocols.

/services/data-recovery/ssd/

USB Flash Drive Data Recovery

Recover lost data from USB flash drives, regardless of the damage or brand. We offer free in-lab evaluations to assess data recovery needs.

/services/data-recovery/usb-flash-drive/

If you’re unsure about which data recovery service to choose, let our team assist you in selecting the appropriate solutions. We understand the anxiety that comes with a sudden drive failure, and we are more prompt in our actions compared to other recovery service providers.