Cybersecurity firm Emsisoft is helping victims of BlackMatter ransomwareby providing them with a decryption tool. This has been in place since the summer and has prevented millions of dollars from being paid to cybercriminals.
Emsisoft and its CTO, Fabian Wosar, have been helping ransomware victims recover their files since 2012, when ACCDFISA emerged as the first modern ransomware.
See also: FBI, CISA and NSA issue advisories on BlackMatter ransomware attacks

Since then, Wosar and other researchers have been trying to find flaws in ransomware encryption algorithmsso that they can create decryption tools for victims.
However, Emsisoft operates in secret so that ransomware gangs are unaware of the existence of the flaws in their algorithms. The security company does not make public announcements, but quietly works with trusted law enforcement partners and helps victims.
Emsisoft has created a secret decryption tool for BlackMatter ransomware
Shortly after the BlackMatter ransomware went live, Emsisoft discovered a bug that allowed it to create a decryption tool so victims could recover files without paying a ransom to the criminals.
Emsisoft immediately notified law enforcement authorities, ransomware negotiation companies, incident response firms, the CERTs and other trusted partners and informed them about the decryption tool for the BlackMatter ransomware.
Thanks to this notification, partners were able to refer BlackMatter victims to Emsisoft to recover their files without paying a ransom.

“Since then, we have been busy helping victims of the BlackMatter ransomware recover their data. With the help of law enforcement agencies, CERTs, and private sector partners in multiple countries, we have been able to reach many victims, helping them avoid paying tens of millions of dollars,” explains Wosar.
See also: BlackMatter ransomware: Demands 5.9 million from agricultural cooperative
Additionally, Emsisoft was communicating with victims who were uploading ransomware samples to various sites. This allowed it to help a large number of victims.
“We have been fighting ransomware for over ten years, so we understand the frustration the infosec community feels towards ransomware threat actors,” Wosar shared.
However, the researchers initially could breach the negotiation conversations between hackers and victims through the samples and the ransomware notes that were published. And thus they could contact victims to tell them not to pay the ransom.
As the victims began refusing to pay, BlackMatter grew increasingly suspicious and shut down its platform, so that only the victim could access the site for negotiations.
Additionally, criminals began to put more pressure on victims and negotiators. One negotiator told BleepingComputer that he began receiving death threats from the BlackMatter gang after none of the victims of an attack paid the ransom.

Unfortunately, the BlackMatter ransomware gang learned about the decryption tool in late September and managed to fix the bugs that allowed Emsisoft to recover victims' files.
See also: Italian celebrities' data exposed in ransomware attack on SIAE
Victims who were affected by ransomware attacks before the end of September can still use the decryption tool to avoid paying the ransom.
Those who have been affected by the BlackMatter ransomware after the bug fix can no longer be helped, but Emsisoft suggests they contact it to see if they can help in some way.
Emsisoft has found vulnerabilities in about a dozen active ransomware operations, which can be used to recover victims' encrypted data without paying a ransom.
The security company advises victims to contact law enforcement authorities to report attacks, so that Emsisoft is also notified and checks whether a decryption tool is available.
Source: Bleeping Computer
