HomeSecurityZorab ransomware: Beware! It is presented as a ransomware decryptor

Zorab ransomware: Beware! Posing as a ransomware decryptor

Zorab ransomware

Recently, a fake tool for the STOP Djvu Ransomware has been circulating, luring desperate victims by promising to “free” their encrypted data . However, this does not happen. Instead, the supposed ransomware decryptor infects systems with another ransomware (Zorab) that makes the situation even worse.

The most well-known ransomware are Maze, REvil, Netwalker , and DoppelPaymer. However, STOP Djvu ransomware infects more people on a daily basis.

With over 600 attacks per day, STOP Djvu is the most widely distributed ransomware in the last year.

Emsisoft and Michael Gillespie had released a ransomware decryptor for older versions of STOP Djvu, but newer versions cannot be decrypted for free with this tool.

But why has such a common ransomware, which constantly carries out attacks, not attracted as much attention as others?

The lack of attention is mainly due to the fact that ransomware affects home users who are infected via adware that masquerades as software cracks.

Η διπλή κρυπτογράφηση των δεδομένων με ένα δεύτερο ransomware είναι “χτύπημα κάτω από τη μέση”.

Το Zorab κρυπτογραφεί διπλά τα δεδομένα ενός θύματος

Unfortunately, this tactic is being followed by a new ransomware called Zorab , discovered by Michael Gillespie.

The creators of Zorab ransomware have released a fake decryption tool for STOP Djvu, which does not restore any files for free. Instead, it re-encrypts all of data by Zorab ransomware.

When the user enters their information into the fake tool and clicks “Start Scan”, the program will extract another executable called crab.exe and save it in the %Temp% folder.

Zorab ransomware

Crab.exe is Zorab ransomware, which starts encrypting data on the computer. When encrypting files, the ransomware will append the .ZRB extension to the file name.

ransomware decryptor

The ransomware also creates a ransom note named “–DECRYPT – ZORAB.txt.ZRB”. This note contains instructions on how to make the payment and how to contact the ransomware operators.

ransomware decryptor

Zorab ransomware is under analysis. Users should not pay the ransom. However, if they absolutely must, they should wait until it is confirmed that there is no free way to decrypt and recover data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS