HomeSecurityAvaddon ransomware: Spanish student distributes free decryptor to victims

Avaddon ransomware: Spanish student distributes free decryptor to victims

A Spanish student this week released a free decryption utility that can help victims of Avaddon ransomware recover their files for free. Javier Yuste, a student at the Rey Juan Carlos University in Madrid, shared AvaddonDecrypter on GitHub , which only works in cases where victims have not turned off their computers .

The tool works by dumping the RAM of an infected system and searching the memory contents for data that could be used to recover the ransomware's original encryption key. If enough information is recovered, the tool can then be used to decrypt files, as well as help victims recover from attacks , without having to pay a ransom to the hackers.

Avaddon ransomware: Spanish student distributes free decryptor to victims
Avaddon ransomware: Spanish student distributes free decryptor to victims

It should be noted, however, that while the release of the tool will likely help existing Avaddon victims, it will not help companies that are falling victim to new ransomware attacks. This is because the release of the tool has not gone unnoticed. In a forum post on February 10, the Avaddon gang reported that they learned about the Yuste decryptor and have already deployed updates to code , thus negating the tool’s capabilities.

Avaddon ransomware: Spanish student distributes free decryptor to victims
Avaddon ransomware: Spanish student distributes free decryptor to victims

The Avaddon gang's reaction follows that of the hackers who developed the DarkSide ransomware, who also reacted to the release of a similar decryptor for their own case in January.

Avaddon ransomware: Spanish student distributes free decryptor to victims
DarkSide ransomware

Therefore, the release of both decryption utilities had a very limited impact. While some victims were able to decrypt their files, once the existence of the decryption tools was made public, ransomware gangs analyzed how the tools worked and patched their ransomware code within a few days.

As ZDNet reports, the publication of these two tools, combined with a blog post shared by Dutch security firm Eye Control showing how victims could recover from Data Doctor ransomware attacks, has reignited, once again, a long-standing debate in the cybersecurity about how decryption utilities should be handled and communicated to victims.

Many prominent security researchers with a long history of helping ransomware victims since the mid-2010s have re-emerged in the past couple of months, highlighting the fact that decryption utilities that exploit flaws should remain private and distributed to victims through non-public channels, rather than being advertised online.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS