HomeSecurityFree decryption tool for HermeticRansom ransomware targeting Ukraine

Free decryption tool for HermeticRansom ransomware targeting Ukraine

Avast has released a decryption tool for the HermeticRansom ransomware used in targeted attacks against Ukrainian systems over the past ten days.

The tool is offered for free from Avast's site and can help Ukrainian users restore their data quickly and reliably.

See also: Increased attacks on Ukrainian sites after Russia's invasion of Ukraine

HermeticRansom ransomware decryption tool

The first signs of the distribution of the HermeticRansom ransomware were observed by ESET researchers on February 23, shortly before the invasion of Russian troops into Ukraine.

The ransomware was delivered along with a computer worm called HermeticWizard and served more as bait for wiper attacks than as a means of financial extortion. However, it has affected significant systems in Ukraine.

Crowdstrike identified a weakness in the ransomware's cryptographic scheme (which is written in GO) and offered a script to decrypt files encrypted by HermeticRansom (also known as PartyTicket).

“The ransomware contains application bugs, allowing for the encryption to be ‘broken’. This bug suggests that the malware’s creator either lacked Go experience or did not test the malware sufficiently, possibly because the development time available was limited,” Crowdstrike explains in a new post released on Tuesday.

See also: Microsoft: Ukraine was attacked by FoxBlade malware before the invasion

As it turns out, the HermeticRansom ransomware that targeted Ukrainian networks was not created as a modern ransomware strain with the dual purpose of extortion and causing financial or reputational damage to the victim. However, this does not mean that HermeticRansom infections do not affect targeted machines.

ransomware Ukraine

Instead, this ransomware can encrypt valuable files outside of the Program Files and Windows folders, using an RSA-2048 key.

The ransom note that victims saw has a standard format and content, asking them to contact a ProtonMail address to obtain a decryption.

HermeticRansom ransomware: Avast releases new decryption tool

Although Crowdstrike's script is reliable, it is not easy for everyone to use. That's why Avast has released a GUI decryption tool that makes it easier to decrypt files affected by HermeticRansom ransomware.

See also: Anonymous renames Putin's yacht to "FCKPTN"

The tool also offers the option to create backup copies of encrypted files, so that the files are not lost if something goes wrong with the encryption process.

For more details about the Avast tool and how to use it, click here.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS