HomeSecurityBitdefender: Free decryptor for DarkSide victims!

Bitdefender: Free decryptor for DarkSide victims!

Romanian cybersecurity company Bitdefender released a free decryptor on January 11 that can help victims of the DarkSide ransomware recover their encrypted fileswithout having to pay the ransom demanded by the gang’s hackers. The decryptor, currently available for download on Bitdefender’s website, along with instructions for use, is a breath of hope for companies whose important files were encrypted by one of the most sophisticated ransomware operations operating in cyberspace today.

DarkSide is a ransomware operation that has already made millions since it began targeting businesses in August 2020. The operation saw a spike in activity between October and December 2020, when the number of DarkSide samples on the ID-Ransomware platform more than doubled.

Bitdefender: Free decryptor for Darkside victims!

The group uses a well-established Ransomware-as-a-Service (RaaS) model to collaborate with other criminal groups. These groups apply for DarkSide RaaS and receive a fully functional version of the ransomware. They then compromise companies using their own chosen methods, install the ransomware, and demand huge ransoms from victims. Specifically, ransom demands range from $200,000 to $2,000,000, depending on the size of the compromised organizations.

As ZDNet reports, this is not a new modus operandi. It is the so-called "big game hunting" in which ransomware gangs mostly target high-profile companies, rather than individual home users, in an attempt to make as much profit as possible.

In cases where victims refused to pay the ransom, DarkSide operators leaked documents stolen from the network to a data leak site, as a form of punishment and warning to other victims who may want to restore data from backups instead of paying the ransom.

Bitdefender: Free decryptor for Darkside victims!

While DarkSide has been publishing the names and details of new victims on its site for about a year, the group is believed to still be active.

According to MalwareHunter, the most recent activity from the group is an update to its site from last week, in which DarkSide operators added a new section dedicated to journalists, where journalists can register and communicate with the DarkSide gang.

ransomware

While most DarkSide victims have paid the ransom or restored files from backups months ago, the DarkSide decryptor is not useless for the following reasons:

  • It helps companies recover important files that were encrypted months ago and which they were unable to restore, but are still stored on backup drives.
  • It increases operational costs for the DarkSide gang, which will now have to redo all codes to prevent free decryptions.
  • It deals a significant blow to DarkSide RaaS. Many ransomware businesses have shut down in the past after releasing a free decryptor, as most of their customers abandoned them for “unencryptable” competitors.

As for victims, the free decryptor released by Bitdefender should, in theory, work for all recent versions of DarkSide ransomware, regardless of the file extension that the hackers added to the end of each encrypted file. This extension is unique per victim, as it is calculated from local characteristics, but this is not a problem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS