New Zealand-based cybersecurity firm Emsisoft has released a free decryption tool to help users/organizations that have been attacked by the AstraLocker and Yashma ransomware . Thanks to this tool, victims can recover their files without paying a ransom .

The free tool is available for download from Emsisoft's servers and allows recovering encrypted files easily, thanks to the instructions available in this user guide [PDF].
See also: QNAP: Checkmate ransomware targets NAS devices
“Make sure you quarantine the malware from your system, otherwise it may repeatedly lock your system or encrypt files,” Emsisoft warned.
“By default, the decryptor will pre-populate the locations for decryption with the currently connected drives and network drives. Additional locations can be added using the Add button“.
Emsisoft advised victims of AstraLocker and Yashma ransomware who were compromised via Windows Remote Desktopto change the passwords for all accounts user that have remote login privileges and to look for other local accounts that ransomware operators may have added.

The decryption tool for the AstraLocker ransomware was released a few days after the ransomware developer announced that it was shutting down its operations and releasing a decryption program for victims.
“It was fun and fun things come to an end. I’m closing the business, the decryption tools are in files zip,” the AstraLocker developer reportedly told BleepingComputer. “I’m done with ransomware for now. I’m going to cryptojack, lol.”
See also: Fake copyright complaints distribute IcedID malware via Yandex Forms
According to researchers, AstraLocker is based on the Babuk Locker (Babyk) ransomware, whose source code was leaked in September on a hacking forum.
This is not the first time that a ransomware developer has released decryption keys. This usually happens when the hackers retire from the business (as happened now) or when new versions of the malware are released. In the past, decryption tools have been released for Ragnarok, Avaddon, SynAck, AES-NI, Shade, FilesLocker, TeslaCrypt, Crysis, Ziggy, and FonixLocker ransomware.
See also: Quantum ransomware: Attack affects 657 healthcare organizations
However, regarding AstraLocker and Yashma ransomware, victims can now also choose Emsisoft's free decryption tool.
Source: www.bleepingcomputer.com
