GandCrab has become one of the most devastating, and hence most successful, ransomware families of 2018. Alongside the Dharma cryptovirus family, GandCrab has enslaved the files of millions of users in a number of active campaigns via several iterations. This is the list of all the versions of the ransomware:
Fortunately for all the victims, GandCrab’s story is coming to an end – BitDefender researchers have come up with a free decryption tool that uses an RSA-2048 private key. The tool recovers files affected by GandCrab ransomware. Such files can be recognized by the extensions the ransomware appends to compromised files as well as via the ransom note.
As noted by the researchers, for this solution to work, you should have at least one ransom note on your computer. This ransom note is required to recover the decryption key, meaning that you should not deploy a clean-up program which typically detects and removes these notes. Specific instructions on how to decrypt files encrypted by Gandcrab for free are also available.
The news about the free decryptor arrives shortly after the ransomware authors released decryption keys specifically for citizens of Syria. This occurred after a Syrian victim asked for help with the recovery of his encrypted data in a tweet. Photographs of his deceased children, casualties of the civil war in Syria, were among the files affected by the ransomware. Eventually, GandCrab’s operators noticed the tweet and responded with a post on a forum, which stated that keys (Read more...)
*** This is a Security Bloggers Network syndicated blog from The State of Security authored by Tripwire Guest Authors. Read the original post at: https://www.tripwire.com/state-of-security/featured/files-encrypted-by-gandcrab-ransomware-can-now-be-decrypted-for-free/
Leading UK Credit Card Consumer Finance Company Uses Advanced Graph Analytics to Intercept Fraudulent Credit Card Applications, Boost Anti-Fraud Efforts…
Digital+ Partners Leads Continuation Funding Round in Growing Automated Threat Analysis & Detection Provider, Closing its Series B Round at…
For three years OpenWRT had a severe validation problem with its download package manager, until a fuzz tester found and…
It’s time to say a final “Goodbye” to Flash. (Or should that be “Good riddance”?) With earlier this week seeing…
1. Be a student of (information security, network security, cyber security). Always strive to know what the latest tactics, trends,…
This is the second in a series of blog posts that discuss how smart DNS resolvers can enhance ongoing network…