HomeSecurityKey Group ransomware: Decryption tool restores files for free

Key Group ransomware: Decryption tool restores files for free

Security researchers from EclecticIQ have exploited a vulnerability in the encryption system of the Key Group ransomware and managed to create a decryption tool that allows some victims to recover files for free. The tool works for versions of the ransomware created in early August.

Key Group ransomware decryption tool

The attackers claimed that their malware used “military-grade AES encryption,” but the locker uses static salt in all encryption processes. Thus, the encryption scheme was somewhat predictable to researchers and allowed for the possibility of reversing the encryption.

“The Key Group Ransomware encrypts victims’ data using the AES algorithm in Cipher Block Chaining (CBC) mode with a given static password,” explains EclecticIQ.

“The password is derived from a key using Password-Based Key Derivation Function 2 (PBKDF2) with a fixed salt,” the researchers report.

See also: Trojanized Signal and Telegram apps infected users with BadBazaar spyware

Key Group ransomware

Key Group is a Russian hacking group that began its activities in early 2023. It has attacked various organizations and stolen data from compromised systems. The hackers then use private Telegram to negotiate ransom payments.

Russian company BI.ZONE previously reported that the Key Group gang has based its ransomware on the Chaos 4.0 builder. EclecticIQ has seen the group selling stolen data and SIM, as well as sharing doxing data and remote access to IP cameras.

Regarding how the ransomware works, Key Group deletes the original files from the victim's system after the encryption process, and applies the .KEYGROUP777TG to the encrypted files.

See also: New Ransomed ransomware group uses a new extortion tactic

Additionally, attackers use Windows living-off-the-land binaries, so-called LOLBins, to delete Volume Shadow copies, making it impossible for users to recover their data without paying a ransom.

Additionally, the malware changes the host addresses of antivirus products running on the system so that they cannot receive new updates.

Key Group ransomware: Decryption tool restores files for free

Key Group ransomware: Decryption tool

EclecticIQ's decryption tool is a Python script. Users can save it as a Python file and then run it using the following command:

python decryptor.py /path/to/search/directory

The script will search the target directory and its subdirectories for files with the .KEYGROUP777TG extension. It will then decrypt them and save the content with the original filename. Note that some Python libraries are required, especially the cryptography package.

Before using the decryption tool for Key Group ransomware, it is a good idea to back up (encrypted) data , as the process may lead to data corruption and permanent loss.

See also: Ransomware attack hits Ohio History Connection

The release of this tool could enable the Key Group gang to address the vulnerabilities in its ransomware, in order to create more resilient versions of its malicious software. However, the individuals affected by the current ransomware versions can recover their data for free.

However, it is important to remember the importance of proactive security measures and constant updates to protect against malware. First of all, use up-to-date security software that includes ransomware protection. Second, regularly back up your important data to external hard drives or the cloud. Third, be mindful of your digital footprint, don't open suspicious attachments, and don't click on untrusted links. Finally, stay informed about new threatsso you can recognize and avoid them.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS