ESET has announced that it has started making available a decryption tool for AES-NI to users whose data has been encrypted by Win32/Filecoder.AESNI.B and Win32/Filecoder.AESNI.C (also known as XData).
The decryption tool for AES-NI is based on keys recently released via Twitter and a help forum for ransomware victims.
As Ondrej Kubovič, Security Specialist at ESET, explains: “The decryption tool is intended for files encrypted by the offline RSA key, which is used by the AES-NI variant B adding the .aes256, .aes_ni and .aes_ni_0day extensions, as well as for the XData variant, which adds the .~xdata extension to the infected files.”
Users who have fallen victim to the ransomware and still have their files encrypted can download the decryptor from ESET's dedicated help tools page. The ESET Knowledgebase page provides more information on how to use the tool and details on specific cases where the decryptor cannot help.
Those interested can find more details about what happened that seems to have led to the “end” of this particular malware. Useful information on ransomware protection is available on ESET’s official blog, WeLiveSecurity.
https://download.eset.com/com/eset/tools/decryptors/aesni/latest/esetaesnidecryptor.exe
