Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Crime Encryption Security IT

CoinVault and Bitcryptor Ransomware Victims Can Now Recover Their Files For Free (itworld.com) 32

itwbennett writes: Researchers from Kaspersky Lab and the Dutch Public Prosecution Service have obtained the last set of encryption keys from command-and-control servers that were used by CoinVault and Bitcryptor,' writes Lucian Constantin. 'Those keys have been uploaded to Kaspersky's ransomware decrypt or service that was originally set up in April with a set of around 750 keys recovered from servers hosted in the Netherlands.
This discussion has been archived. No new comments can be posted.

CoinVault and Bitcryptor Ransomware Victims Can Now Recover Their Files For Free

Comments Filter:
  • by SumDog ( 466607 ) on Saturday October 31, 2015 @08:43AM (#50837555) Homepage Journal

    I've never been hit by one of these, but I realize it can cost people a lot of money due to some shitheads. I'm really glad a lot of these keys have been found and made public. I'm sure this won't be the end of ransomware...people will just use new keys, but hopefully this will help some of those who have clicked on a not-a-flash upgrade or bad e-mail attachment.

    • by Zocalo ( 252965 ) on Saturday October 31, 2015 @09:19AM (#50837611) Homepage
      While it's a worthy effort, I suspect that it's mostly just a PR stunt though since I doubt very many people will actually be able to use these keys to avoid paying the ransom, given that the criminals will indeed switch to new keys pretty much overnight, potentially re-encrypting any data on PCs they have already compromised in the process if they can re-establish control via other C&C servers. Of the potential victims that could benefit from this, once you've eliminated those who have already paid the ransom, written off their data and started over, or were fortunate enough to have good backups to restore from, are there *really* going to be that many left who will also be capable of finding the site with the decryption tools on it? That we don't here the security companies trumpting the numbers of successful decryptions using recovered keys like these makes me think that there are probably not all that many.
      • by Xenna ( 37238 ) on Saturday October 31, 2015 @10:13AM (#50837751)

        "While it's a worthy effort, I suspect that it's mostly just a PR stunt though since I doubt very many people will actually be able to use these keys to avoid paying the ransom, given that the criminals will indeed switch to new keys pretty much overnight, potentially re-encrypting any data on PCs they have already compromised in the process if they can re-establish control via other C&C servers."

        AFAIK the guys who did it are now in jail, which makes it a lot harder to change keys. Evene if they didn't catch them all, the remaining bad guys may want to lay low for a while.

        So, it looks pretty much like a success to me. Locking these guys up and retrieving the keys is pretty much the best you can do in such a case.

        • by Zocalo ( 252965 )
          I'm not saying it's not a success or worth doing, just that it's perhaps not *quite* the degree of success that it might seem. Keeping in mind that there likely to be lots of groups trying out this kind of scam, each using their own sets of keys and potentially also distributing them across multiple C&C servers to help mitigate against this kind of countermeasure, then the number of victims for a given C&C server is likely to be quite low to start with. According to the site iteself [kaspersky.com] there are arou
          • by Xenna ( 37238 )

            Again AFAIK these schemes install a trojan on your system which generates a unique private/public key pair. The private key is sent to the C&C server and stored while the public key is used to encrypt the data and discarded after use. They could even use symmetric encryption since key exchange is not a big problem in this scenario. In any case a new key is generated for each victim and sent back to the C&C server. If this is true, the 15000 keys would correspond to the number of victims (not files).

      • by Kjella ( 173770 )

        From what I understand these trojans give you a countdown timer before they wipe the key, so I think very few would keep an encrypted system around past that date on the very unlikely chance that the keys will be found somehow. People might drag their feet while the timer is running, but afterwards I expect 99.9%+ will fix their computer wiping the encrypted drive in the process.

        • by plover ( 150551 )

          I would be surprised if they wipe the keys as fast as the countdown timers claim. Once they wipe a key, they can make 0 money from it. It would be smarter to threaten to jack the rates: "pay us by Tuesday or we double the ransom."

          These guys provided 14,000 keys to Dutch law enforcement. It sure sounds like they didn't wipe them.

      • by muphin ( 842524 )
        The way ransomware works is it encrypts your files, sends the key to a C&C server, then deletes itself so it cannot be intercepted and key reverse engineered.
        so the criminals wont be able to encrypt the files as there’s no way to communication with the infected machine.
    • Had quite a few customers hit with these. One was running a legacy xBase app and it even encrypted the DBF files! Luckily they had a backup only a few hours old.
    • I've never been hit by one of these, but I realize it can cost people a lot of money due to some shitheads. I'm really glad a lot of these keys have been found and made public. I'm sure this won't be the end of ransomware...people will just use new keys, but hopefully this will help some of those who have clicked on a not-a-flash upgrade or bad e-mail attachment.

      I hope they recovered the keys from the shitheads using this technique [xkcd.com].

    • by f3rret ( 1776822 )

      I've never been hit by one of these, but I realize it can cost people a lot of money due to some shitheads. I'm really glad a lot of these keys have been found and made public. I'm sure this won't be the end of ransomware...people will just use new keys, but hopefully this will help some of those who have clicked on a not-a-flash upgrade or bad e-mail attachment.

      The droppers for these things are usually based in websites, no clicking on sketchy attachments required. Simply a plausible(ish) looking e-mail from a plausible(ish) sounding organization with a link to a site that will use a browser exploit of some kind and drop the thing onto the computer.

  • by Anonymous Coward on Saturday October 31, 2015 @08:45AM (#50837561)

    they are truly good guys. Most of their competitors, F-Secure being the exception I guess, would have charged money for this service, or not even bother in the first place.

  • So the article says it's 750 keys.

    Why do they have a decryption service ?

    Why do we need to upload files ? Which could be a privacy problem, annoying when dealing with large numbers of files or large files.

    Why not publish the keys ?

    And maybe make a small program to make it easier to decrypts files.

  • Much Respect! (Score:4, Insightful)

    by JustAnotherOldGuy ( 4145623 ) on Saturday October 31, 2015 @11:27AM (#50837991) Journal

    A big salute to the people at Kaspersky Labs and the Dutch Public Prosecution Service.

    Talk about earning goodwill, these guys (and gals) just banked a mountain of it as far as I'm concerned.

    • Re:Much Respect! (Score:5, Interesting)

      by plover ( 150551 ) on Saturday October 31, 2015 @11:50AM (#50838055) Homepage Journal

      This certainly isn't their only cool act of public service, either. I saw one of the Dutch guys presenting an interesting topic at Black Hat: How to preserve a powered on system during a raid using mouse jigglers and UPSes, and collecting forensic evidence while preserving chain of custody, good practical advice. The BH crowd eats that stuff for breakfast, but he was providing info that is useful to help train non-technical officers executing a warrant.

  • by Anonymous Coward

    I dont see why this is even an option. Randomly fry your files, claim encryption, hold for ransom, get money, vanish. Its not like they are operating legally anyway....

  • by Anonymous Coward

    http://finance.yahoo.com/news/fbi-recommends-pay-hackers-infect-185625373.html [yahoo.com]

    Joseph Bonavolonta, the Assistant Special Agent who oversees the FBI’s CYBER and Counterintelligence Program in Boston, spoke at the 2015 Cyber Security Summit and advised that companies infected with ransomware may want to give in to the criminal’s demands.

    “The ransomware is that good,” Bonavolonta explained to an audience of business and technology leaders during the Q&A. “To be honest, we often

E = MC ** 2 +- 3db

Working...