New version of Petya Released. Fixes bug in Encryption Algorithm

Av Gurus

Level 29
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
A new version of the Petya disc-encrypting ransomware has been released that fixes a bug that previously caused some weakness in its encryption algorithm. According to Hasherezade, a security analyst for Malwarebytes, prior versions of the Petya ransomware were not properly implementing the Salsa20 encryption algorithm, which was used by the ransomware to encrypt the drive and for verifying that a correct ransom key was entered.

With this new version, the Petya developer's implementation of the Salsa20 algorithm has been fixed, which removes the previously exploitable weaknesses.



View image on Twitter
CnkUE9eWYAAQCvS.jpg:large


Follow
hasherezade @hasherezade

new #Petya #ransomware is out, and finally they got Salsa20 implemented correctly... so, be warned and keep safe

2:39 PM - 17 Jul 2016




It appears that Petya is still pretending to be a PDF file, but it is unsure how the ransomware is being distributed or what filename it uses. Like the previous version, when installed Petya will attempt to gain administrative privileges in order to install the disc encryptor, and if it fails, will install theMischa file encrypting ransomware instead.

green-petya.png

Petya Lock Screen
If Petya is still being distributed like previous versions, human resource departments for companies, especially German companies, should be wary of any applicants that request you download resumes that have a name like Bewerbungsmappe. In the past, this method was used to trick people into running the installer for Petya.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Creating a unique ransomware is definitely hard, in the sense all of patterns are recorded already.

So instead, improving the existing ransomware is not a bad idea cause automatically any AV will be bypass.
 

NekoHr

Level 3
Verified
Well-known
Feb 5, 2016
139
Malware authors do same unnecessary thing as lot of security people of reinventing the wheel, making new crypto. Crypto is solved, it works if implemented properly (unfortunately in this case).

One thing that is changing and improving is method of infection.
 
  • Like
Reactions: Cats-4_Owners-2

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top