Overslaan naar hoofdinhoud

Victory. Again: Kaspersky Lab Finds a Way to Unlock Files Encrypted with CryptXXX Ransomware

20 december 2016

After releasing decryption tools for two variants of CryptXXX ransomware in April and May 2016, Kaspersky Lab is releasing a new decryptor for files that have been locked with the latest version of the malware

After releasing decryption tools for two variants of CryptXXX ransomware in April and May 2016, Kaspersky Lab is releasing a new decryptor for files that have been locked with the latest version of the malware. This malicious program was capable of infecting thousands of PCs around the world since April 2016, and it was impossible to fully decrypt the files affected by it. But not anymore.

The free RannohDecryptor toolby Kaspersky Lab can decrypt most files with .crypt, .cryp1 and .crypz extensions.

CryptXXX is one of the most actively distributed and dangerous families of ransomware: for a long time criminals used the Angler and Neutrino exploit kits to infect victims with this malware. These two kits were considered among the most effective in terms of successfully infecting targets.  

Since April 2016, Kaspersky Lab products have registered attacks by CryptXXX against at least 80,000 users around the world. More than half of them located in only six countries: the US, Russia, Germany, Japan, India and Canada. 

Victory

But these are only users that were protected by Kaspersky Lab’s detection technologies. Unfortunately the total number of attacked users is much higher. The actual figure is not known, but Kaspersky Lab experts estimate that there may be several hundred thousand infected users.

“Our regular advice to the victims of different ransomware families is the following: even if there is currently no decryption tool available for the version of malware that encrypted your files, please don’t pay the ransom to criminals. Save the corrupt files and be patient – the probability of a decryption tool emerging in the near future is high. We consider the case of CryptXXX v.3 as proof of this advice. Multiple security specialists around the world are continuously working hard to be able to help victims of ransomware. Sooner or later the solution to the vast majority of ransomware will be found,” - said Anton Ivanov, security expert at Kaspersky Lab.

Learn more about ransomware on Securelist.com

The decryption tool can be downloaded from Kaspersky Lab’s website and from Nomoreransom.org – the website of the not-for-profit initiative launched this year by the National High Tech Crime Unit of the Netherlands’ police, Europol’s European Cybercrime Centre and two cyber security companies, Kaspersky Lab and Intel Security, with the goal of helping victims of ransomware to retrieve their encrypted data without having to pay the criminals.

Victory. Again: Kaspersky Lab Finds a Way to Unlock Files Encrypted with CryptXXX Ransomware

After releasing decryption tools for two variants of CryptXXX ransomware in April and May 2016, Kaspersky Lab is releasing a new decryptor for files that have been locked with the latest version of the malware
Kaspersky logo

Over Kaspersky

Kaspersky is een internationaal bedrijf dat is opgericht in 1997 en dat is gespecialiseerd in cyberbeveiliging en digitale privacy. Dankzij de uitgebreide bedreigingsintelligentie en beveiligingsexpertise van Kaspersky zijn tot nu toe meer dan een miljard apparaten beschermd tegen opkomende cyberbedreigingen en gerichte aanvallen. Kaspersky transformeert voortdurend haar innovatieve oplossingen en diensten om bedrijven, kritieke infrastructuren, overheden en consumenten wereldwijd te beschermen. Onder het allesomvattende beveiligingsportfolio van Kaspersky vallen toonaangevende endpointbescherming, gespecialiseerde beveiligingsproducten en diensten, evenals Cyber Immune-oplossingen waarmee geavanceerde en evoluerende digitale bedreigingen kunnen worden bestreden. We helpen meer dan 200.000 zakelijke klanten te beschermen wat het belangrijkste voor ze is. Meer informatie vind je op www.kaspersky.nl.

Verwant artikel Information