Now the victims of the MarsJoke ransomware can recover their files, using a Decrypter that was created by the security experts at Kaspersky Lab and is available for free download.
MarsJoke ransomware, also known as JokeFromMars or Polyglot, is a ransomware variant that first appeared two weeks ago, spread by malicious spam messages with an emphasis on the government and K-12 education sector.
The ransomware was quite active and caught the attention of many independent security researchers, as well as the staff of major security vendors such as Proofpoint and Kaspersky.
The latter announced today that they managed to identify a weakness in the ransomware's encryption routine which they used to create a free decrypter, which is provided for free download from their site (the RannohDecryptor tool).
Kaspersky Lab experts warn that this Decrypter only works for current versions of the ransomware and that future iterations may not exhibit the same issue that allows the Decrypter to recover the encryption keys.
Researchers cite previous incidents involving CryptXXX ransomware, in which Kaspersky experts broke the encryption three times and created free decrypters, but in the end, the CryptXXX authors identified the encryption bug and fixed it for good.
Malware analysts who looked more closely at the MarsJoke ransomware said that the ransomware appears to be the work of a talented coder.
Despite this, its creators made a great effort to create a graphic almost identical to the CTB-Locker ransomware, which even today, is still undecryptable.
“Despite the obvious similarities between Polyglot and CTB-Locker, they are two completely different types of malware. They share almost no code at all”, Kaspersky explained yesterday. “Our experts believe that by mimicking the CTB-Locker appearance, the Polyglot creators are trying to confuse researchers.”
According to Kaspersky, the MarsJoke author made a mistake in the ransomware module that generates the encryption keys. This error allowed researchers to create the Decrypter.
For now, MarsJoke ransomware victims can relax. However, if the ransomware is updated regularly, the Decrypter is expected to stop working within the coming weeks.


