Security News More Security Firms Confirm NotPetya Shoddy Code Is Making Recovery Impossible

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
...some quotes:

The bandwagon of cyber-security firms claiming that NotPetya was meant for destructive purposes is getting more crowded by the day, with three new additions from Cisco Talos, F-Secure, and Malwarebytes.

This theory was first put forward two days ago by security researchers from Comae Technologies and Kaspersky Lab, who found evidence that the ransomware was bungling its encryption routine and using random data to display the infection ID, respectively.

Both companies highlighted the fact that the NotPetya;s faulty encryption routine was making recovery impossible. Coupled with Ukraine's political context, many experts suggested this was a cyber-weapon designed to destroy as many systems as possible before a Ukrainian national holiday.

Malwarebytes, Cisco, and F-Secure issue reports

In the past two days, other cyber-security companies have confirmed the initial findings. For example, this is the conclusion of a Malwarebytes report published yesterday:

"According to our current knowledge, the malware is intentionally corrupt in a way that the Salsa key was never meant to be restored. Nevertheless, it is still effective in making people pay ransom. [...] If you are a victim of this malware and you are thinking about paying the ransom, we warn you: Don’t do this. It is a scam and you will most probably never get your data back."
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top