HomeSecurityCerber Ransomware v2 spotted online | It is now Undecryptable

Cerber Ransomware v2 Detected Online | It Is Now Undecryptable

Cerber, the most active ransomware last month, received a major update in recent weeks, breaking a previous decryption tool that allowed users to recover their files for free, without paying the ransom.

Cerber itincluded a feature where it read the ransom message aloud in various languages.

Cerber Ransomware v2 Detected Online | It Is Now Undecryptable

As time went on, this clever ransomware became one of the most common threats we've seen today, mainly because researchers failed to crack it and crooks started to trust it more.

This happened a few weeks ago, when researchers at Trend Micro created an all-purpose ransomware decrypterthat could recover encrypted files locked by certain ransomware families, including Cerber.

Since then, it appears that the crook behind Cerber has continued to work on his tool, updating it to fix this encryption routine and break the decrypter.

According to Trend Micro researcher, PanicAll, there have been two new major releases to Cerber, v1.5 and v2.

The first changed the encryption routine while the second changed the extension added to the end of each encrypted file, which now became .cerber2, instead of the previous .cerber.

Technically, Cerber v2 uses the CryptGenRandom Microsoft API to generate encryption keys, which are now 32 bytes long, instead of 16 bytes.

Configuring Cerber v2 prevents the ransomware from launching on computers running security software such as ArcaBit, ArcaVir, Avast, Bitdefender, BullGuard, CA, Emsisoft, ESET, eTrust, F-Secure, Kaspersky, Lavasoft, and TrustPort.

Additionally, the ransomware will not launch if it detects OS languages ​​for the following countries: Armenia, Azerbaijan, Belarus, Georgia, Kyrgyzstan, Kazakhstan, Moldova, Russia, Turkmenistan, Tajikistan, Ukraine, and Uzbekistan.

V2 now targets 456 file types for its encryption routine, making it by far one of the most widespread ransomware variants. Cerber has also updated ransom screen , which now looks something like this:

online-undecryptable

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS