Security researchers from EclecticIQ have exploited a vulnerability in the encryption system of the Key Group ransomware and managed to create a decryption tool that allows some victims to recover files for free. The tool works for versions of the ransomware created in early August.

The attackers claimed that their malware used “military-grade AES encryption,” but the locker uses static salt in all encryption processes. Thus, the encryption scheme was somewhat predictable to researchers and allowed for the possibility of reversing the encryption.
“The Key Group Ransomware encrypts victims’ data using the AES algorithm in Cipher Block Chaining (CBC) mode with a given static password,” explains EclecticIQ.
“The password is derived from a key using Password-Based Key Derivation Function 2 (PBKDF2) with a fixed salt,” the researchers report.
See also: Trojanized Signal and Telegram apps infected users with BadBazaar spyware
Key Group ransomware
Key Group is a Russian hacking group that began its activities in early 2023. It has attacked various organizations and stolen data from compromised systems. The hackers then use private Telegram to negotiate ransom payments.
Russian company BI.ZONE previously reported that the Key Group gang has based its ransomware on the Chaos 4.0 builder. EclecticIQ has seen the group selling stolen data and SIM, as well as sharing doxing data and remote access to IP cameras.
Regarding how the ransomware works, Key Group deletes the original files from the victim's system after the encryption process, and applies the .KEYGROUP777TG to the encrypted files.
See also: New Ransomed ransomware group uses a new extortion tactic
Additionally, attackers use Windows living-off-the-land binaries, so-called LOLBins, to delete Volume Shadow copies, making it impossible for users to recover their data without paying a ransom.
Additionally, the malware changes the host addresses of antivirus products running on the system so that they cannot receive new updates.

Key Group ransomware: Decryption tool
EclecticIQ's decryption tool is a Python script. Users can save it as a Python file and then run it using the following command:
python decryptor.py /path/to/search/directory
The script will search the target directory and its subdirectories for files with the .KEYGROUP777TG extension. It will then decrypt them and save the content with the original filename. Note that some Python libraries are required, especially the cryptography package.
Before using the decryption tool for Key Group ransomware, it is a good idea to back up (encrypted) data , as the process may lead to data corruption and permanent loss.
See also: Ransomware attack hits Ohio History Connection
The release of this tool could enable the Key Group gang to address the vulnerabilities in its ransomware, in order to create more resilient versions of its malicious software. However, the individuals affected by the current ransomware versions can recover their data for free.
However, it is important to remember the importance of proactive security measures and constant updates to protect against malware. First of all, use up-to-date security software that includes ransomware protection. Second, regularly back up your important data to external hard drives or the cloud. Third, be mindful of your digital footprint, don't open suspicious attachments, and don't click on untrusted links. Finally, stay informed about new threatsso you can recognize and avoid them.
Source: www.bleepingcomputer.com
