.Better_Call_Saul is a ransomware distributed via spam emails with infected .doc files attached. After a successful infiltration, this ransomware encrypts various files stored on the system. To encrypt them, the ransomware uses the RSA-256 algorithm and, as a result, public and private keys are created during encryption.

Note that this ransomware adds an extension of the same name (.better_call_saul) to the end of each encrypted file. In addition, it changes the user's wallpaper and creates a README1.txt file in each folder containing the encrypted files.

The text file and wallpaper contain a message that the files are encrypted and that to restore them, the victim must pay a ransom.