HomeSecurityCryptonite ransomware: It can't decrypt files – it just destroys them

Cryptonite ransomware: Can't decrypt files – just destroys them

If you have been affected by the Cryptonite ransomware, experts advise not to bother paying the ransom. This is due to the fact that this particular ransomware cannot decrypt files – only destroys them.

See also: Hackers are cracking down on Linux devices using the PRoot tool

Cryptonite ransomware

Cryptonite ransomware, written in the Python, first appeared in October. It is part of an open-source toolkit that can be downloaded for free and used by anyone with the necessary skills to launch attacks against Microsoft Windows. Phishing attacks are believed to be the most common method of spreading Cryptonite ransomware.

But after Fortinet researchers analyzed Cryptonite, they found that the ransomware had only limited functionality and no way to decrypt files – even if you paid the ransom.

Instead, Cryptonite effectively acts as a malware wiper, destroying encrypted files, leaving no way to recover the data.

Although it may seem that Cryptonite ransomware is intentionally trying to destroy files, researchers believe that this result is due to the low quality of the ransomware's design.

The ransomware is poorly made, resulting in it not functioning correctly. The design flaw means that if Cryptonite crashes or shuts down, there is no way to recover the encrypted files.

See also: Scattered Spider Hackers: How They Carry Out Their Attacks

Also, there is no way to run it in decryption-only mode – so each time the ransomware is executed, it re-encrypts everything with a different key. This means that, even if there were a way to recover the files, the unique key probably would not work.

Ransomware victims often pay a ransom to restore access to their network . But even after paying this payment , they may not be able to get their systems back online.

Cryptonite ransomware: Can't decrypt files – just destroys them

The case of Cryptonite ransomware is a reminder that paying ransoms does not guarantee that hackers will provide a decryption key or that it will work properly.

Several cybersecurity organizations, such as CISA, the FBI , and the NCSC, recommend against paying ransoms because it empowers and encourages cybercriminals. Criminals are more likely to attack again if they know they can get away or if the ransomware is easily accessible at little or no cost.

See also: CISA asks organizations to protect against new Chrome zero-day bug

The positive news is that it is now more difficult for beginner hackers to obtain Cryptonite, as the original source code has been deleted from GitHub.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS