Hades family ransomware decryption tool

B2B Cyber ​​Security ShortNews

Share post

Luckily, ransomware programmers make mistakes too, so Avast's specialists were able to develop a decryption tool for the Hades family's MafiaWare666 ransomware. MafiaWare666 is also known as JCrypt, RIP Lmao or BrutusptCrypt.

Avast releases MafiaWare666 ransomware decryption tool. MafiaWare666 is a ransomware strain written in C# that does not contain any obfuscation or anti-analysis techniques. It encrypts files using AES encryption. Avast discovered a vulnerability in the encryption scheme that allows decrypting some of the variants without paying the ransom. New or previously unknown samples may encrypt files differently, so they may not be decryptable without further analysis.

Targeting classic file folders

MafiaWare666 reported this blackmail (image: Avast).

The ransomware scans specific folder locations such as Desktop, Music, Videos, Pictures, and Documents and encrypts files. These files get a new extension that varies depending on the example: .MafiaWare666, .jcrypt, .brutusptCrypt, .bmcrypt, .cyberone, .l33ch. The ransomware then displays a window with instructions on how to pay the ransom. The instructions instruct victims to contact the attacker and pay in Bitcoin. The ransom price is relatively low, ranging from $50 to $300, although some of the older specimens with other names charge much more, up to a bitcoin which is around $20.000 at the time of publication.

Decryption with free tool

Avast now offers a decryption tool for free. Handling is very easy. After the tool runs, it searches a specified target drive. If it finds encrypted files there, the tool tests which password is the correct one. If found, the bulk decryption process starts.

More at Avast.com

 


About Avast

Avast (LSE: AVST), a FTSE 100 company, is a leading global provider of digital security and privacy products. Avast has over 400 million online users and offers products under the Avast and AVG brands that protect people from threats from the Internet and the evolving IoT threat landscape. The company's threat detection network is one of the most advanced in the world, using technologies like machine learning and artificial intelligence to detect and stop threats in real time. Avast's digital security products for mobile, PC or Mac have been top-rated and certified by VB100, AV-Comparatives, AV-Test, SE Labs and other test institutes.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

[starbox id=USER_ID] <🔎> ff7f00