CryptXXX Ransomware Decrypter Available for Download

A

Alkajak

Thread author
cryptxxx-ransomware-decrypter-available-for-download-503436-2.png cryptxxx-ransomware-decrypter-available-for-download-503436-3.png

Today, Kaspersky Lab has released an updated version of the RannohDecryptor ransomware decryption toolkit that can also handle CryptXXX infections.

CryptXXX is one of the most recently discovered ransomware variants that have surfaced in the past week. The ransomware works just like any other piece of crypto-ransomware we've seen on the market in the last few months, but this is not the most dangerous detail about its mode of operation.

According to Proofpoint researchers, the ransomware is distributed by a well-oiled cyber-crime machine that has also distributed in the past malware such as the Reventon ransomware and the Bedep clickfraud malware.

Besides encrypting files, the ransomware also collects a lot of personal information from infected computers and even tries to steal Bitcoin from cryptocurrency wallets.

Nevertheless, Kaspersky researchers were able to find a weak point in the ransomware's operations and have adapted their RannohDecryptor to handle this new threat.

In order to discover the encryption key that CryptXXX used to lock the victim's files, users need to have an unencrypted copy of an encrypted file, so the decrypter can compare the two.

After RannohDecryptor obtains the decryption key, users only need to tweak the application's settings for their local PC setup and run it to start decrypting files.

Depending on the number of files CryptXXX locked, it will take a few hours to decrypt all your data, so give it some time. Furthermore, the decrypter only unlocks your files, and you'll still need an antivirus with malware removal capabilities to delete any remnants of CryptXXX from your system.
 

omidomi

Level 71
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Apr 5, 2014
6,008
Kaspersky researchers have managed to crack the CryptXXX ransomware code and have issued a free tool for users to get their files back without paying a fee.

The ransomware, dubbed CryptXXX, was first discovered by Proofpoint researchers in April. While standard ransomware variants do nothing more than encrypt your files and demand a ransom fee -- most often in Bitcoin, but demands can also vary to include commodities such as Apple iTunes gift cards -- this new strain of ransomware is different.

CryptXXX not only encrypts your files using the .crypt extension, but takes things a lot further -- by encrypting files on any attached data storage devices, rifling through your compromised system to steal sensitive data, and taking away any cryptocurrency Bitcoin reserves you have.

Once the malware finds its way onto a system through a malicious download, CryptXXX encrypts the hard drive and creates three files, all of which display the ransom demand as a desktop wallpaper, browser web page and text file.

The ransomware claims the system has been locked with the help of the RSA4096 encryption algorithm and demands $500 in Bitcoin for files to be decrypted.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top