HomeSecurityEmsisoft: Free decryption tool for AstraLocker and Yashma ransomware

Emsisoft: Free decryption tool for AstraLocker and Yashma ransomware

New Zealand-based cybersecurity firm Emsisoft has released a free decryption tool to help users/organizations that have been attacked by the AstraLocker and Yashma ransomware . Thanks to this tool, victims can recover their files without paying a ransom .

AstraLocker Yashma ransomware decryption tool

The free tool is available for download from Emsisoft's servers and allows recovering encrypted files easily, thanks to the instructions available in this user guide [PDF].

See also: QNAP: Checkmate ransomware targets NAS devices

“Make sure you quarantine the malware from your system, otherwise it may repeatedly lock your system or encrypt files,” Emsisoft warned.

“By default, the decryptor will pre-populate the locations for decryption with the currently connected drives and network drives. Additional locations can be added using the Add button“.

Emsisoft advised victims of AstraLocker and Yashma ransomware who were compromised via Windows Remote Desktopto change the passwords for all accounts user that have remote login privileges and to look for other local accounts that ransomware operators may have added.

Emsisof ransomware decryption tool

The decryption tool for the AstraLocker ransomware was released a few days after the ransomware developer announced that it was shutting down its operations and releasing a decryption program for victims.

“It was fun and fun things come to an end. I’m closing the business, the decryption tools are in files zip,” the AstraLocker developer reportedly told BleepingComputer. “I’m done with ransomware for now. I’m going to cryptojack, lol.”

See also: Fake copyright complaints distribute IcedID malware via Yandex Forms

According to researchers, AstraLocker is based on the Babuk Locker (Babyk) ransomware, whose source code was leaked in September on a hacking forum.

This is not the first time that a ransomware developer has released decryption keys. This usually happens when the hackers retire from the business (as happened now) or when new versions of the malware are released. In the past, decryption tools have been released for Ragnarok, Avaddon, SynAck, AES-NI, Shade, FilesLocker, TeslaCrypt, Crysis, Ziggy, and FonixLocker ransomware.

See also: Quantum ransomware: Attack affects 657 healthcare organizations

However, regarding AstraLocker and Yashma ransomware, victims can now also choose Emsisoft's free decryption tool.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS