Alfa Ransomware is not decryptable at this moment. The encryption cannot be broken at this time. When infecting a PC, Alfa will scan all the local drives for certain file types, up to 142 different file types are targeted. In these documents, victims will get a unique ID to be used to login to the TOR-based payment site, where they are required 1 Bitcoin ransom as the only solution to get their files back. Victims will then delete the Volume Shadow Copies on the victims computer, stopping users from recovering the unencrypted files.”]
Source: https://blog.360totalsecurity.com/en/cerber-developers-release-alfa-ransomware/

