HomeSecurityKaseya REvil ransomware: Company acquires decryption key

Kaseya REvil ransomware: Company acquires decryption key

American software company Kaseya, which recently made headlines after a ransomware attack that affected it and several other companies, now has access to the master decryption key for the REvil ransomware.

Kaseya decryption key
Kaseya REvil ransomware: Company acquires decryption key

The company announced yesterday its access to the decryption tool, about 20 days after the attack that took place on July 2.

The attack affected 60 Kaseya customers and approximately 1,500 of those companies' customers. Many of the victims, who used Kaseya software, were left facing problems for days due to the ransomware attack.

According to Kaseya, security firm Emsisoft has confirmed that the decryption key unlocks files encrypted by REvil ransomware.

See also: Kaseya: Warns of phishing campaign promoting fake security updates

Kaseya REvil ransomware

“We can confirm that Kaseya has acquired the tool and we have teams assisting customers in restoring their environments, with no reports of any problems or issues related to the decryption tool,” Kaseya said in a statement.

See also: Kaseya: Former employees had reported vulnerabilities years ago

Kaseya is working with Emsisoft to assist customers affected by this incident.

A customer, whose name we do not know, said last week that he paid a ransom to the REvil ransomware gang, but was unable to decrypt his files with the decryption key given to him by the hackers.

The REvil gang's sites were taken offline last week when US President Joe Biden pressured Russian President Vladmir Putin to take action to crack down on the actions of Russian-based cybercriminals targeting American companies.

Learn more: REvil Ransomware: Gang's sites down

Biden reportedly told Putin that critical infrastructure should be protected. We are not forgetting the problems created after the DarkSide gang's ransomware attack on Colonial Pipeline.

REvil decryption

It is unclear whether Kaseya paid the $70 million ransom demanded by the hackers. A Kaseya spokesperson told The Guardian that the company obtained the decryption tool from a “trusted source.”.

While some of the victims of the attack managed to restore their systems, others remained offline. Therefore, this decryption tool can help a large number of companies.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS