back to top

Kaspersky releases tool for decrypting ransomware that was used against businesses and state institutions

In late February 2023, Kaspersky experts uncovered a new portion of leaked data published on forums.

Kaspersky has published a new version of a decryption tool that helps victims of a ransomware modification based on a previously leaked Conti source code. Conti is a ransomware gang that has dominated the cybercrime scene since 2019, and whose data, including the source code, was leaked in March 2022 following an internal conflict caused by the geopolitical crisis in Europe.

The discovered modification was distributed by an unknown ransomware group and has been used against companies and state institutions.

In late February 2023, Kaspersky experts uncovered a new portion of leaked data published on forums. After analyzing the data, which contained 258 private keys, the source code and some pre-compiled decryptors, Kaspersky released a new version of the public decryptor to help victims of this modification of Conti ransomware.

Conti appeared in late 2019 and was very active throughout 2020, accounting for more than 13% of all ransomware victims during this period. However, a year ago, once the source code was leaked, multiple modifications of Conti ransomware were created by various criminal gangs and used in their attacks.

The malware variant whose keys were leaked was discovered by Kaspersky specialists in December 2022. This strain was used in multiple attacks against companies and state institutions.  The leaked private keys are located in 257 folders (only one of these folders contains two keys). Some of them contain previously generated decryptors and several ordinary files: documents, photos, etc. Presumably the latter are test files – a couple of files that the victim sends to the attackers to make sure that the files can be decrypted.

Thirty-four of these folders have explicitly named companies and government agencies. Assuming that one folder corresponds to one victim, and that the decryptors were generated for the victims who paid the ransom, it can be suggested that 14 victims out of the 257 paid the ransom to the attackers.

After analyzing the data, the experts released a new version of the public decryptor to help victims of this modification of the Conti ransomware. The decryption code and all 258 keys were added to the latest build of Kaspersky’s utility RakhniDecryptor 1.40.0.00. Moreover, the decryption tool has been added to Kaspersky’s No Ransom site (https://noransom.kaspersky.com).

“For many consecutive years, ransomware has remained a major tool used by cybercrooks. However, because we have studied the tactics, techniques and procedures (TTPs) of various ransomware gangs and found out that many of them operate in similar ways, preventing attacks becomes easier. The decryption tool against a new Conti-based modification is already available on our No Ransom webpage. However, we would like to emphasize that the best strategy is to strengthen defenses and stop the attackers at early stages of their intrusion, preventing ransomware deployment and minimizing the consequences of the attack,” said Fedor Sinitsyn, lead malware analyst at Kaspersky.

Latest

Elon Musk’s xAI teams up with Telegram in $300M deal to bring Grok to a billion users

Telegram CEO Pavel Durov announced the partnership via social...

OpenAI’s $6.5 billion deal brings Apple design legend Jony Ive onboard, marking their largest acquisition

This marks OpenAI’s largest acquisition to date and signals...

Global gas demand to rise 50% by 2030, says Woodside CEO at WGC

At the World Gas Conference, Meg O’Neill, CEO of Australia’s top natural gas producer Woodside Energy, predicted a sharp 50% spike in global gas demand by 2030.

Qatar Airways takes off with single largest widebody aircraft order with $96 billion Boeing-GE mega deal

Doha’s national carrier is set to redefine global aviation...
spot_img

Don't miss

National Life and General Insurance Company: Delivering value beyond insurance to customers

Oman’s largest insurer NLGIC is on course to become a regional multi-line, multi-country giant delivering value beyond insurance to the customers.

AI central to UAE’s economic diversification, says COP28 President-Designate

AI will contribute to the UAE’s net zero strategic initiative by 2050 and help unlock advances in climate progress, says H.E. Dr. Sultan Ahmed Al Jaber, UAE Minister of Industry and Advanced Technology.

Economic growth in GCC to more than halve in 2023: World Bank report

However, the GCC growth will still outperform the wider Middle East and North Africa region, forecast to grow by 3% in 2023, down from 5.8% growth in 2022.

KitchenomiKs aims to transform on-demand food economy in Oman

KitchenomiKs cooks up dainty on-demand delicacies, tossing in emerging technologies, yummy multi-brand choices and seamless delivery.

Real estate sector in GCC experiencing ‘profound transformation’: Expert

The real estate sector in the GCC region is...
spot_imgspot_img

Elon Musk’s xAI teams up with Telegram in $300M deal to bring Grok to a billion users

Telegram CEO Pavel Durov announced the partnership via social media, confirming that the encrypted messaging service will distribute Grok, xAI’s artificial intelligence chatbot, across...

OpenAI’s $6.5 billion deal brings Apple design legend Jony Ive onboard, marking their largest acquisition

This marks OpenAI’s largest acquisition to date and signals its first major leap into the world of AI-powered hardware. OpenAI, the maker of ChatGPT, is...

Launch your startup in just 60 minutes with Dubai’s latest service

Dubai continues to cement its reputation as a global hub for innovation and entrepreneurship with the launch of Fawri, a new digital platform by...