An alert from the US Federal Bureau of Investigation (FBI) regarding the Mamba ransomware reveals a weak spot in the encryption process that could help targeted organizations recover from the attack without paying the ransom demanded by the hackers.

The FBI warns that Mamba ransomware attacks have targeted public and private sector entities, including local governments, transportation agencies, legal services, technology services, industrial, commercial, manufacturing, and construction businesses.
See also: FBI: Warns of increased Pysa ransomware attacks on educational institutions
Mamba ransomware (also known as HDDCryptor) relies on an open-source software solution called DiskCryptor to encrypt victims' computers in the background with a key defined by the attacker.
The FBI explains that installing DiskCryptor requires a system reboot to add the necessary drivers, which occurs approximately two minutes after the program is deployed.
The FBI also notes that the encryption key and the termination time variable are stored in DiskCryptor's configuration, a plaintext file called myConf.txt.
See also: FBI: Cybercrime losses reached $4.2 billion in 2020!
A second system reboot occurs once the encryption process is complete, approximately two hours later, and the ransom note becomes available.
Because there is no protection around the encryption key, as it is stored in plain text, the FBI says this two-hour gap is an opportunity for organizations affected by the Mamba ransomware to recover it.
The company behind the Mamba ransomware began to increase activity with a new variant found in the second half of 2019. Despite not having an affiliate program, it was among the top threats.
Also read: FBI-CISA: Phishing emails distribute known malware
In a report by Coveware, Mamba was among the top five ransomware threats in the first quarter of last year – with REvil and Ryuk in the top spots. That changed in the fourth quarter of 2020, though it continued to be a notable threat.
A peculiarity of Mamba ransomware is that it overwrites the disk's master boot record (MBR), blocking access to encrypted files on the drive. This makes it more difficult to track the number of attacks, as the files cannot be analyzed by automated services such as ID-Ransomware.
Information source: bleepingcomputer.com
