The encryption of Gomasom Ransomware – How to recover your files
Users who were unfortunate enough to be infected with the ransomware now have the ability to recover their files, thanks to security researcher Fabian Wosar of Emsisoft, who managed to create a decryption tool for victims of the malware.
Gomasom, also known as Google Mail Ransomware, is a relatively recent arrival on the malware market, with its activity limited to the past few weeks.
H λειτουργία του έγκειται στο να μολύνει τους χρήστες και στη συνέχεια να κρυπτογραφεί τα αρχεία τους, αφήνοντας μια διεύθυνση Gmail στο όνομα του κάθε αρχείου και προσθέτοντας την επέκταση αρχείου “.crypt”.
However, Gomasom no longer appears to be a threat as security researcher Fabian Wosar has created a tool with which users are able to analyze an encrypted file and obtain decryption key .
When the user obtains the key, this tool can be used to decrypt the rest of its files.
The optimal result is achieved when the user has access not only to the encrypted version of a file, but also to its original form.
If not, there is an alternative solution, as users can select an encrypted PNG file and compare it with a random PNG file from the Internet.
The results of this method, however, may not be as expected, and it should also be noted that in the case of a large volume of encrypted data, the decryption process may take a longer period, perhaps more than a day.
The decryption tool for the Gomasom ransomware is available from Emsisoft's website.

