Gandcrab developers show empathy towards Syrian ransomware victims

Last week, an individual with a particularly acute ransomware story took to twitter to plead for help, reaching out to us in the process.

We claim no credit whatsoever for the end result (we get a large volume of fictitious and malicious inbound that looks substantially similar every day), but we’re glad to see the resolution.  The visibility of the individual’s outreach was picked up by other outlets and caught the attention of the GandCrab ransomware developers. In a display of empathy, the GandGrab developers released decryption keys for all victims of Syrian origin. Not adding Syria to the original block list was a mistake they admitted.

Gandcrab ransomware is unique in that the developers have invested a great deal in the payment and decryptor tool delivery infrastructure. That investment likely paid off in this instance as they were able to programmatically make a change to their TOR payment site to allow residents of Syria to download decryptor tools for free.

This example of ransomware developers releasing decryption keys is not entirely unique. There are other examples of hackers releasing publicly accessible decryption keys after their campaigns end.  When decryption is not urgent we always counsel clients to preserve copies of encrypted data. When decryption tools or keys are publicly released those who preserve their data have the ability to make a full recovery.

*** This is a Security Bloggers Network syndicated blog from Blog | Latest Ransomware News and Trends | Coveware authored by Bill Siegel. Read the original post at: https://www.coveware.com/blog/2018/10/23/gandcrab-developers-show-empathy-towards-syrian-ransomware-victims

Bill Siegel

Bill Siegel is the CEO and Co-founder of Coveware, a ransomware incident response firm. Before founding Coveware, Bill Siegel was the CFO of SecurityScorecard, a NY based cyber security ratings company. Prior to SecurityScorecard, Bill was the CEO of Secondmarket, and served as the Head of NASDAQ Private Market following Nasdaq’s acquisition of SecondMarket in 2015.

Recent Posts

NewDay Scores with TigerGraph Cloud to Fight Financial Fraud

Leading UK Credit Card Consumer Finance Company Uses Advanced Graph Analytics to Intercept Fraudulent Credit Card Applications, Boost Anti-Fraud Efforts…

50 mins ago

VMRay Closes $25 Million Series B

Digital+ Partners Leads Continuation Funding Round in Growing Automated Threat Analysis & Detection Provider, Closing its Series B Round at…

3 hours ago

The Hacker Mind Podcast: Hacking OpenWRT

For three years OpenWRT had a severe validation problem with its download package manager, until a fuzz tester found and…

3 hours ago

Goodbye to Flash – if you’re still running it, uninstall Flash Player now

It’s time to say a final “Goodbye” to Flash. (Or should that be “Good riddance”?) With earlier this week seeing…

3 hours ago

Being a Defender

1. Be a student of (information security, network security, cyber security). Always strive to know what the latest tactics, trends,…

4 hours ago

Smart DNS: Delivering the Best Subscriber Experience

This is the second in a series of blog posts that discuss how smart DNS resolvers can enhance ongoing network…

4 hours ago