HomeSecurityMaze/Egregor ransomware: Decryption keys released

Maze/Egregor ransomware: Decryption keys released

The master decryption keys for the Maze, Egregor, and Sekhmet ransomware were released last night on the BleepingComputer forums by a user claiming to be the malware.

Maze Egregor ransomware

The Maze ransomware emerged in May 2019 and quickly stood out as its operators were the ones who started stealing data before encrypting networks and threatened to leak it if the ransom was not paid. This technique, known as the double extortion technique, has now been adopted by most ransomware gangs.

See also: Avast: Free decryption tool for TargetCompany ransomware victims

In October 2020, it was announced that the Maze ransomware operation was shutting down, but the gang resurfaced under a different name: Egregor. It later disappeared as well, after members were arrested in Ukraine.

Operation Sekhmet began in March 2020, while the Maze team was still active.

Master decryption keys released

The decryption keys for these ransomware operations have now been leaked on the BleepingComputer forums by a user named “Topleak,” who claims to be the developer of the above malware.

The user reported that this was a planned leak unrelated to recent law enforcement operations.

“… it is necessary to emphasize that this is a planned leak and has nothing to do with recent arrests and server shutdowns,” the alleged ransomware developer explained.

See also: Fake Windows 11 upgrade installers infect you with RedLine malware

He also said that none of his team members will return to ransomware operations and that they have destroyed the source code for their ransomware.

Maze/Egregor ransomware: Decryption keys released
Maze/Egregor ransomware: Decryption keys released

The post includes a download link for a 7zip archive with four files containing the decryption keys for Maze, Egregor, and Sekhmet, and the source code for a 'M0yv' malware used by the ransomware gang.

decryption keys

RSA-2048 master decryption keys for every ransomware enterprise:

  • Maze: 9 master decryption keys for the original malware that targeted non-corporate users.
  • Maze: 30 master decryption keys.
  • Egregor: 19 master decryption keys.
  • Sekhmet: 1 master decryption key.

Michael Gillespie and Fabian Wosar of Emsisoft reviewed the decryption keys and confirmed to BleepingComputer that they are legitimate and can be used to decrypt files.

See also: ESET: What were the most popular attack methods in 2021?

Emsisoft has also released a decryption tool that allows all victims of Maze, Egregor, and Sekhmet to recover their encrypted files for free.

To use the tool, victims will need the ransom note created during the attack, as it contains the encrypted decryption key.

M0yv malware: Source code

The file also includes the source code for the M0yv 'modular x86/x64 file infector' developed by the operators of the Maze ransomware and used in attacks.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS