HomeSecurityNew ransomware encrypts files with Google employee tool

New ransomware encrypts files with Google employee tool

AgeLocker ransomware

A new ransomware called AgeLocker uses the “Age” encryption tool , created by a employee Google , and encrypts victims’ files

Ransomware has recently targeted some people. An analysis of the encrypted files showed that a header was added to each file , starting with the URL “age-encryption.org”, as shown below.

Google

Here is an example of the header that was added to an encrypted file:

age-encryption.org/v1 -> X25519 O9LABKJJggKQAsCbCQzPQFz0XwOHXSljEJU2xwS3zHA Ildq7HXhtndUkpcHnz1+jnFjkpPK8wrVbDSbYXye2wg --- Rwz4uNO8q6DbP1gbGuSVIA7W2wUKNluxyvMHuAJNIyM

The URL age-encryption.org leads the victim to a GitHub repositoryfor an encryption utility called “Age” created by Filippo Valsorda, a cryptographer and key security executive at Google.

According to the Age manual, the utility was designed as a replacement for GPG for encrypting “files, backups, and streams.” It’s called “Age,” which is probably an acronym for “Actually Good Encryption.”

Instead of creating ransomware that uses common encryption algorithms (e.g. AES + RSA), the hackers behind the AgeLocker ransomware use Age to encrypt their victims' files.

Ransomware decryption expert Michael Gillespiesaid that Age uses the X25519, ChaChar20-Poly1305, and HMAC-SHA256. This is a secure method of encrypting files.

AgeLocker ransomware ransom note sent via email

We still don't know how the hackers to gain access to victims' computers, but once they do, they use the tool to encrypt files.

During data encryption , an extension is appended to the encrypted files, which includes the initials of the victim's name.

In one of the initial infections, AgeLocker ransomware did not leave a ransom note on the encrypted system. The attackers sent an email to the victim informing them of the attack and the amount of money they wanted.

After encrypting the company's systems (in this case), victims received an email with the subject “[company name] security audit”.

In this email, the hackers list the devices encrypted by AgeLocker ransomware and provide instructions on how to pay the ransom.

Hello XXX and XXX, Unfortunately a malware has infected your network and millions of files have been encrypted using a hybrid encryption scheme. File names encrypted too. Encrypted hosts are: Storage: 1. XXX 2. XXX 3. XXX 4. XXX 5. XXX Mac + external drives 1. XXX? 2. XXX? 3. XXX 4. XXX 5. XXX 6. XXX You have to pay for decryption in Bitcoins. The price depends on how fast you write us. After payment we will send you the tool (for mac and linux) that will decrypt all your files. Free decryption as guarantee Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 4Mb (non archived), and files should not contain valuable information. (databases, backups, large excel sheets, etc.), file name should not be changed. How to obtain Bitcoins The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price. https://localbitcoins.com/buy_bitcoins Also you can find other places to buy Bitcoins and beginners guide here: https://www.coindesk.com/information/how-can-i-buy-bitcoins/ Attention! Do not rename encrypted files. Do not try to decrypt your data using third party software, it may cause permanent data loss. Note: we can answer up to 6-9 hours, because of another timezone."

According to the victim, the attackers are demanding 7 bitcoins, or approximately $64,500, for decrypting the files.

Currently, there is no free way to recover encrypted files.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS