Noransom from Kaspersky for those infected by CoinVault
Victims of the CoinVault ransomware program now have the opportunity to recover their data without paying anything to the criminals behind the attack, thanks to special keys and a decryption application available online from Kaspersky Lab and the Dutch Police's Cybercrime Unit (NHTCU).
The keys and the tool are available on the website noransom.kaspersky.com, along with clear instructions for users on how to apply them.
The ransomware program COINVAULT, which has been active here for quite some time, encrypts victims' files and demands Bitcoins to unlock them. To help victims recover their files after an attack, the NHTCU and the Dutch National Prosecutor's Office seized a database from a CoinVault Command & Control server. This server contained Initialization Vectors (IVs), keys and private Bitcoin wallets. This helped Kaspersky Lab and the NHTCU develop the dedicated site where decryption keys are made available. Since the research is ongoing, new keys will be added as soon as they become available.
“If a user has been infected by CoinVault, they can visit noransom.kaspersky.com, where we have uploaded a huge number of keys. If there are currently no files available for a specific Bitcoin wallet type, they can check back soon, as we are constantly updating the relevant information, in cooperation with the Dutch Police’s Cybercrime Unit,” said Jornt van der Wiel, Researcher in Kaspersky Lab’s Global Research and Analysis Team.
The CΟΙΝVΑULΤ has infected over 1,000 Windows computers in more than 20 countries, with the majority of victims located in the Netherlands, Germany, the USA, France and the United Kingdom. Victims have also been reported in Belgium, Austria, Switzerland, Norway, Sweden, Luxembourg, Denmark, Slovakia, Slovenia, Spain, Italy, Hungary, Ireland, Croatia, Russia, Canada, Israel, the United Arab Emirates, China, Indonesia, Thailand, South Africa, Australia, New Zealand, Panama, the Dominican Republic and Mexico.
“Many believe that fighting digital crime requires cooperation between the public and private sectors. And that is exactly what we are doing. We all need to talk to our partners and see how we can contribute to achieving the common goal, which is none other than maintaining digital security,” commented Marijn Schuurbiers of the Dutch Police’s Cybercrime Unit.
Kaspersky Lab security experts also analyzed the malware samples and developed a decryption tool that can unlock files and delete the CINVAULT malware from infected computers.
To find out how to remove CoinVault ransomware from your computer and restore your files, visit https://noransom.kaspersky.com/.
How can the «infection» be prevented? Keep your anti-malware software up to date and regularly create backups of your most important files.
Kaspersky Lab solutions detect this malware "family" under the codename "Trojan-Ransom.Win32.CrypmodadV.cj".
Source: secnews.gr



