[News](/news)

Ransomware payments drop to $9.99

[Blog](/blog)[Breaches](/breaches)[Resources](/resources)[News](/news)

# Ransomware payments drop to $9.99

##### [Edward Kost](/team/edward-kost)

April 18, 2021

The average online ransom price in 2020 was $312,439 - a 3x increase from 2019 - and it’s expected to surge further upwards in 2021. But a certain ransomware gang, known as NitroRansomware, has applied a generous discount to this pricing, charging victims only $9.99 to decrypt their seized data.

The small ransom amounts aren’t paid in cash or Bitcoin; they’re subscription upgrades for the instant messaging solution Discord.

Like most successful SaaS products, Discord converts website visitors into paying customers by utilizing a freemium model - a marketing strategy where a basic product is offered for free, but money is charged for feature upgrades.

By upgrading to Discord’s paid subscription “Nitro” you’ll benefit from HD video streaming, larger file uploads, two server boosts, and enhanced emojis. Nitro upgrades can also be purchased as gift cards for friends.

Not a bad offering for only $9.99 a month.

But to one thrifty group of cybercriminals, this pricing was unacceptable.

Unwilling to forsake their frugality, NitroRansomware established a ransomware deployment workflow to benefit from the enhanced functionality of the Nitro product without spending a dime.

The malicious sequence starts with a seemingly innocuous offer of a free Nitro code generator - ironically targeting avaricious victims that also want to upgrade to Nitro without paying for it.

Once the fake tool is installed, the ransomware is deployed, and the encryption process begins. A changed wallpaper showing an angry Discord logo marks the encryption as complete.

Then, an eerie ransomware message is displayed, demanding the submission of a purchased Nitro gift code within 3 hours in exchange for a complete reversal of the damage. 

All submitted Nitro gift code URLs are verified using the Discord API URL. Once verified the decryption process is initiated.

Besides personal file encryption, NitroRansomware performs additional malicious activities, such as stealing a victim’s Discord tokens and attempting remote access to execute foreign commands.

But NitroRansomware’s backdoor is rudimentary, and its decryption key is terribly hidden, so users could decrypt their files without succumbing to the ransom demands. 

This suggests that the ransomware was developed in haste, possibly as more of an entertaining experiment rather than a serious threat - a window into the concerning proficiency of[ ransomware development](https://www.upguard.com/blog/what-is-ransomware-as-a-service).

## How secure is Discord?

Discord operates a communication platform that provides voice, video, and text chat services for users to connect while gaming or socializing. The service allows users to create customizable servers and communities, with features including streaming, screen sharing, and integrated activities.

* View our free preliminary report on Discord’s security posture
* 13 risk factors, including email security, SSL, DNS health, open ports and common vulnerabilities

[View Discord's score](/security-report/discord)

[View score](/security-report/discord)

[https://discord.com/](/security-report/discord)

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

## Latest news

Stay up-to-date with the latest news in cybersecurity.

[](/news/hugging-face-data-breach-2026-07-20)

#### [Hugging Face data breach: key facts and what we know so far](/news/hugging-face-data-breach-2026-07-20)

A data breach involving Hugging Face was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 20, 2026

[](/news/ey-data-breach-2026-07-19)

#### [EY data breach: what happened and what's at risk](/news/ey-data-breach-2026-07-19)

A data breach involving EY was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

#### [South Florida Injury & Convenient Care data breach exposes names and Social Security numbers](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

A data breach involving South Florida Injury & Convenient Care was reported in July 2026. See incident details, impact on customers, and security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/park-west-psychology-data-breach-2026-07-16)

#### [Park West Psychology data breach: what happened and what's at risk](/news/park-west-psychology-data-breach-2026-07-16)

A data breach involving Park West Psychology was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

#### [Fall River Municipal Credit Union data breach: what happened and what's at risk](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

A data breach involving Fall River Municipal Credit Union was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [](#)

July 14, 2026

[](/news/npcil-data-breach-2026-07-16)

#### [NPCIL data breach: World Leaks claims exposure of Kudankulam Nuclear Power Plant files](/news/npcil-data-breach-2026-07-16)

A data breach involving NPCIL was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 14, 2026

[View all news](/news)

## Protect your organization

Get in touch or book a free demo.

[Contact sales](/demo)

[Free demo](/demo)

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
