<span id="hs_cos_wrapper_post_body" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text" ><p>XTBL Ransomware, also known as Shade and Troldesh, is a crypto-ransomware variant originally created in Russia and used in attacks all over the world. XTBL encrypts a user’s files with an “.xtbl” extension, and is mainly spread via spam e-mails.</p> <!--more--><p>While most ransomware attackers go to great efforts to hide themselves, often using TOR, XTBL's creators provide their victims with an e-mail address, which they use to communicate a demand for ransom and dictate a payment method.</p> <p>ThreatSTOP customers are protected from XTBL.</p></span>