Researchers Crack MarsJoke Crypto to Defang Ransomware

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Researchers have cracked the MarsJoke crypto-ransomware, defanging it and giving victims a way to decrypt their files.

Anton Ivanov, Orkhan Mamedov, and Fedor Sinitsyn of Kaspersky Lab’s Anti-Ransom Team explained that the Trojan, which is also known as Polyglot, looks like a knockoff of the classic CTB-Locker ransomware, down to the way it changes victims’ desktop wallpaper, the fact that it lets victims decrypt five files free, and in its identical instructions to victims.

However, the two share almost no code, and are in fact completely different malwares. The researchers suspect that the mimicry was done to throw researchers off and dissuade them from looking under the hood.

“Perhaps the creators of Polyglot wanted to disorient the victims and researchers, and created a near carbon copy of CTB-Locker from scratch to make it look like a CTB-Locker attack and that there was no hope of getting files decrypted for free,” the researchers said in a blog.

The problem is, what’s under the hood is deeply flawed. The main issue is that the creator made a mistake with the key generator.

All of the created keys are based on a randomly generated array of characters. Therefore, the strength of the keys is determined by the generator’s strength. The generator is weak in this case: an exhaustive search of the entire set of the possible keys produced by such a pseudo-random number generator will only take a few minutes on a standard PC.

“Taking advantage of this mistake, we were able to calculate the AES key for an encrypted file,” the researchers explained.

Kaspersky has made a free decryptor available—but warned that the MarsJoke authors could tweak the malware at any time to strengthen it.

Full Article. http://www.infosecurity-magazine.com/news/researchers-crack-marsjoke-crypto/
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top