Kaspersky Releases Conti Decryptor.
2023-03-1712 turns21,662 charstext-davinci-002-render-sha
Summary
Kaspersky released a decryptor to help victims recover data encrypted by a modified Conti ransomware variant.
Messages
Kaspersky releases decryptor for ransomware based on Conti source code
Cybersecurity firm Kaspersky on Thursday released a decryptor that could help victims who had their data locked down by a version of the Conti ransomware.
Kaspersky said the tool can be used on a malware strain that infected dozens of “companies and state institutions” throughout December 2022. Kaspersky did not name the strain, but experts say it’s tracked as the Meow ransomware, which was based on Conti’s leaked code.
Conti’s source code was publicly exposed in March 2022 after a disgruntled affiliate took issue with the group’s support of Russia’s invasion of Ukraine. Kaspersky, which is based in Russia, did not respond to requests for comment about where most of the victims are based.
Experts with the company managed to obtain the ransomware’s private keys – tools given to ransomware victims that allow them to unlock their files.
“In late February 2023, Kaspersky experts uncovered a new portion of leaked data published on forums,” the company said. “After analyzing the data, which contained 258 private keys, source code and some pre-compiled decryptors, Kaspersky released a new version of the public decryptor to help victims of this modification of Conti ransomware.”
A ransomware researcher told BleepingComputer that members of the Meow ransomware group posted in a Russian cybercriminal forum that they were “ceasing” their activities and provided a link to all of the private keys and decryptors.
The analysts found the private keys in 257 different folders – one of the folders had two keys. Several of the folders had decryptors and files used to test the decryptor.
At least 34 of the folders had the names of companies or government agencies and Kaspersky officials said that considering the number of folders with decryptors, they believe 14 victims of the 257 paid a ransom.
Fedor Sinitsyn, lead malware analyst at Kaspersky, said that using the data in the folders, they were able to release a version of a public decryptor and added it to their “No Ransom” catalog of free decryptors.
“For many consecutive years, ransomware has remained a major tool used by cybercrooks. However, because we have studied the TTPs of various ransomware gangs and found out that many of them operate in similar ways, preventing attacks becomes easier,” Sinitsyn said.
Recorded Future ransomware expert Allan Liska said based on the numbers released by Kaspersky, there were a surprisingly low number of victims who paid the ransom. He added that Kaspersky’s work was evidence that ransomware groups themselves typically have lackluster security.
“For all the scolding by ransomware groups of victim organizations we continue to see that ransomware groups themselves are really bad at security. I think poor OPSEC has done in almost as many ransomware groups as government intervention,” he said.
“This is great work by Kaspersky and hopefully we will continue to see more of this type of activity by the public and private sectors. It looks like Kaspersky may have had access to their infrastructure, at least enough to be able to identify victims.”
At its peak, Conti was one of the most prolific ransomware groups operating, attacking dozens of high profile targets including the government of Costa Rica before shutting down in May 2022.
Kaspersky noted that after the Conti source code was leaked, several different variants were created by various criminal gangs.
Kaspersky, a cybersecurity firm, has released a decryptor that can help victims whose data was locked down by a version of the Conti ransomware. The tool can be used on a malware strain that infected multiple companies and state institutions throughout December 2022. While Kaspersky did not name the strain, experts suggest it is the Meow ransomware based on Conti's leaked code. Conti's source code was publicly exposed in March 2022 after a disgruntled affiliate took issue with the group's support of Russia's invasion of Ukraine. Kaspersky obtained the ransomware's private keys and released a public decryptor to help victims of this modification of Conti ransomware. At least 34 of the folders had the names of companies or government agencies, and Kaspersky officials said that considering the number of folders with decryptors, they believe 14 victims of the 257 paid a ransom.
text-davinci-002-render-sha
Woburn, MA – March 16, 2023 – Kaspersky has published a new decryption tool that helps victims of a ransomware modification based on previously leaked Conti source code. Conti is a ransomware gang that has dominated the cybercrime scene since 2019, and whose data, including source code, was leaked in March 2022, following an internal conflict caused by geopolitical crisis in Europe. The discovered modification was distributed by an unknown ransomware group and has been used against companies and state institutions.
In late February 2023, Kaspersky experts uncovered a new portion of leaked data published on forums. After analyzing the data, which contained 258 private keys, source code and some pre-compiled decryptors, Kaspersky released a new version of the public decryptor to help victims of this modification of Conti ransomware.
Conti appeared in late 2019 and was very active throughout 2020, accounting for more than 13 percent of all ransomware victims during this period. However, a year ago, once the source code was leaked, multiple modifications of Conti ransomware were created by various criminal gangs and used in their attacks.
The malware variant whose keys were leaked had been discovered by Kaspersky specialists in December 2022. This strain was used in multiple attacks against companies and state institutions.
The leaked private keys are located in 257 folders (only one of these folders contains two keys). Some of them contain previously generated decryptors and several ordinary files: documents, photos, etc. Presumably the latter are test files – a couple of files that the victim sends to the attackers to make sure that the files can be decrypted.
Thirty-four of these folders have explicitly named companies and government agencies. Assuming that one folder corresponds to one victim, and that the decryptors were generated for the victims who paid the ransom, it can be suggested that14 victims out of the 257 paid the ransom to the attackers.
After analyzing the data, the experts released a new version of the public decryptor to help victims of this modification of the Conti ransomware. The decryption code and all 258 keys were added to the latest build of Kaspersky’s utility RakhniDecryptor 1.40.0.00. Moreover, the decryption tool has been added to Kaspersky’s “No Ransom” site (https://noransom.kaspersky.com).
“For many consecutive years, ransomware has remained a major tool used by cybercrooks,” said Fedor Sinitsyn, lead malware analyst at Kaspersky. “However, because we have studied the TTPs of various ransomware gangs and found out that many of them operate in similar ways, preventing attacks becomes easier. The decryption tool against a new Conti-based modification is already available on our 'No Ransom' webpage. However, we would like to emphasize that the best strategy is to strengthen defenses and stop the attackers at early stages of their intrusion, preventing ransomware deployment and minimizing the consequences of the attack.”
To protect yourself and your business from ransomware attacks, consider following the rules proposed by Kaspersky:
Do not expose remote desktop services (such as RDP) to public networks unless absolutely necessary and always use strong passwords for them.
Promptly install available patches for commercial VPN solutions providing access for remote employees and acting as gateways in your network.
Focus your defense strategy on detecting lateral movements and data exfiltration to the Internet. Pay special attention to the outgoing traffic to detect cybercriminals' connections.
Back up data regularly. Make sure you can quickly access it in an emergency when needed.
Use solutions like Kaspersky Endpoint Detection and Response Expert and Kaspersky Managed Detection and Response service, which help to identify and stop the attack on early stages, before attackers reach their final goals.
Use the latest Threat Intelligence information to stay aware of actual TTPs used by threat actors. The Kaspersky Threat Intelligence Portal is a single point of access for Kaspersky’s TI, providing cyberattack data and insights gathered by our team for 25 years. To help businesses enable effective defenses in these turbulent times, Kaspersky has announced access to independent, continuously updated and globally sourced information on ongoing cyberattacks and threats, at no charge. Request access to this offer here.
The news reports that Kaspersky, a cybersecurity company
text-davinci-002-render-sha
A decryption tool for a modified version of the Conti ransomware could help hundreds of victims recover their files for free.
The utility works with data encrypted with a strain of the ransomware that emerged after the source code for Conti was leaked last year in March [1, 2].
Hundreds of victims encrypted
Researchers at cybersecurity company Kaspersky found the leak on a forum where the threat actors released a cache of 258 private keys from a modified version of the Conti ransomware.
The variant was used in attacks against various private and public organizations over the past year by a ransomware group that some researchers track as MeowCorp.
Ransomware researcher Amigo-A told BleepingComputer that the threat actors published the data on a Russian-speaking forum in February 2022, which contained a link to an archive containing decryption keys, decryptor executables, and the decryptor source code.
Conti-based Meow ransomware operation shares decryption keys
MeowCorp shares decryption keys and source code
source: Amigo-A
Kaspersky analyzed the keys and found them to be associated with a Conti variant they discovered in December 2022. However, the strain had been circulating since at least August.
“The leaked private keys are located in 257 folders (only one of these folders contains two keys),” Kaspersky says in a press release today.
Folders with private keys for Conti-based encryptor Meow
Folders with private keys for the Meow Conti-based encryptor
source: BleepingComputer
BleepingComputer learned that the attacks using the Conti-based encryptor targeted mostly Russian organizations.
The researchers add that some of the folders included previously generated decryptors along with other files, i.e. photos and documents, that were likely used to show victims that the decryption works.
34 of the folders contained explicit names for victim organizations in the government sector in countries in Europe and Asia.
Fedor Sinitsyn, lead malware analyst at Kaspersky, told BleepingComputer that the names in the rest of the folders were hashed or encoded.
Based on this and the number of decryptors available in the leak, Kaspersky says that it can be assumed that the modified Conti strain was used to encrypt 257 victims and that 14 of them paid the attackers to recover locked data.
The private keys were created between November 13, 2022 and February 5, 2023, which is a good indication about the timeline of the attacks. Sinitsyn told us that the infection dates for the victims that contacted Kaspersky for decryption fell into that time range.
Kaspersky added the decryption code and the 258 private keys to its RakhniDecryptor, a tool that can recover files encrypted by more than two dozen ransomware strains.
According to Kaspersky, the decrytor can recover files encrypted by the modified Conti variant that used the following name pattern and extensions:
<file_name>.KREMLIN
<file_name>.RUSSIA
<file_name>.PUTIN
Conti ransomware's demise
For about three years, the Conti gang ran one of the most active and lucrative ransomware-as-a-service operations, targeting big organizations and demanding large ransoms to decrypt the data they locked.
Considered the successor of Ryuk ransomware, the Conti operation started in December 2019 and, with the help of TrickBot operators, it became a dominant threat by July 2020.
The gang wreaked havoc unabated for a year and adopted new tactics (e.g. data theft, leak site) to force victims into paying the ransom.
In August 2021, a disgruntled Conti affiliate leaked information about some of the group members along with the gang’s attack method and training manuals.
The Russian invasion of Ukraine in February last year created more internal friction as core members sided with Russia.
This led a researcher who had been snooping on the operation to leak thousands of messages exchanged between Conti operators and affiliates.
The researcher’s revenge continued through March by leaking the source code for the ransomware encryptor, decryptor, and builder, as well as the administrative panels [1, 2].
It didn’t take long for the operation to break down and in May 2022 the Conti team leaders took offline the infrastructure and announced that the brand no longer existed.
Conti leadership partnered with other gangs in the extortion business and the other members migrated to other ransomware operations.
The U.S. government assesses that Conti was one of the most lucrative ransomware operations, making thousands of victims and amassing more than $150 million in ransom payments.
The damage caused to U.S. companies determined the U.S. Department of State to offer a reward of up to $15 million for information that identified and located Conti leaders and affiliates.
A decryption tool for a modified version
text-davinci-002-render-sha
Security researchers have released a new decryption tool that should come to the rescue of some victims of a modified version of the Conti ransomware, helping them to recover their encrypted data for free.
Conti was one of the most notorious ransomware groups, responsible for hundreds of attacks against organisations, which netted criminals over $150 million. Its victims included the government of Costa Rica which declared a national emergency after systems in multiple departments were severely impacted.
However, things began to unravel for the Conti ransomware gang in February 2022, when the group announced its "full support of the Russian government" after the invasion of Ukraine.
That statement, perhaps understandably, didn't go down well with many people - including people who historically the Conti ransomware group might have considered its partners-in-arms.
Embarrassingly for the criminal gang who extorted millions from businesses by threatening to leak their data, someone chose to leak some 160,000 messages between the Conti group's members, and the source code for the Conti ransomware.
It is this source code that was used to create modified versions of the Conti ransomware, including one which is used by a criminal group sometimes known as MeowCorp.
Image
meow message
Researchers at Russian anti-virus firm Kaspersky have announced that an analysis of data leaked from the Conti group, including the source code, over 250 private keys, and pre-compiled decryptors, has allowed it to create a new free decryption tool for those affected.
Kaspersky believes it has uncovered the private keys required to unlock data files for 257 corporate victims, although 14 may already have paid the ransom to their attackers. The private keys and decryption code have been incorporated into the latest version of Kaspersky's free RakhniDecryptor tool.
According to Bleeping Computer, most of the attacks perpetrated by this modification of the Conti ransomware targeted Russian organisations.
Hopefully it goes without saying that you should back up your important data (even if encrypted) before running any decryption tool, just in case...
In May 2022 the US Department of State offered a reward of up to $10,000,000 for information which would help them identify the leaders of the Conti ransomware group, and a further $5,000,000 for information which helped arrest and/or convict a member of the gang.
It's great news that security researchers at Kaspersky have developed
text-davinci-002-render-sha
1000 words, describe Kaspersky's solution to conti ransomware
Kaspersky, a well-known cybersecurity company, has announced that it has developed a new decryption tool that can help victims of the modified version of Conti ransomware to recover their encrypted data for free. Conti ransomware is a malicious software that encrypts the victim's files and demands a ransom in exchange for the decryption key. The Conti group is notorious for carrying out hundreds of attacks on organizations, and it has made millions of dollars from extorting businesses by threatening to leak their data.
However, in February 2022, the Conti group made an announcement supporting the Russian government's invasion of Ukraine. This statement did not sit well with many people, including those who were once considered the Conti ransomware group's partners-in-arms. As a result, someone leaked 160,000 messages between the Conti group members and the source code for the Conti ransomware.
Using this leaked data, Kaspersky conducted an analysis that allowed it to create a new free decryption tool for those affected by the modified version of the Conti ransomware. The analysis included the source code, over 250 private keys, and pre-compiled decryptors.
According to Kaspersky, it has identified the private keys required to unlock data files for 257 corporate victims. However, 14 of these victims may have already paid the ransom to their attackers. Kaspersky has incorporated the private keys and decryption code into the latest version of its free RakhniDecryptor tool.
It is important to note that most of the attacks perpetrated by this modification of the Conti ransomware targeted Russian organizations, as reported by Bleeping Computer.
The Kaspersky solution is a significant breakthrough for those who have been affected by the modified version of the Conti ransomware. With this free decryption tool, victims can recover their encrypted data without paying the ransom. It is a welcome relief for businesses that may have lost critical data and may not have the resources to pay the ransom.
Kaspersky's solution is a result of its expertise in cybersecurity and its extensive analysis of the leaked data. The company's ability to identify the private keys required to unlock data files for the victims is a testament to its technical capabilities.
The Kaspersky decryption tool is easy to use, and victims can download it from the company's website. However, it is important to note that victims should back up their data before running the decryption tool, just in case.
The development of this new decryption tool by Kaspersky is a significant milestone in the fight against ransomware. It is an important step towards helping victims recover their data without paying a ransom. The tool is also an example of how cybersecurity companies can use their expertise to help those affected by cybercrime.
In May 2022, the US Department of State offered a reward of up to $10,000,000 for information that could help identify the leaders of the Conti ransomware group. A further reward of $5,000,000 was offered for information that helped arrest and/or convict a member of the gang. These rewards demonstrate the severity of the threat posed by ransomware groups such as Conti and the importance of finding ways to combat their activities.
In conclusion, the Kaspersky solution is a significant breakthrough for those affected by the modified version of the Conti ransomware. It is an example of how cybersecurity companies can use their expertise to help victims recover their data without paying a ransom. The Kaspersky decryption tool is easy to use, and victims can download it from the company's website. However, it is important to note that victims should back up their data before running the decryption tool. With the development of this tool, Kaspersky has made a significant contribution to the fight against ransomware, and it is an important step towards helping victims
text-davinci-002-render-sha
How do I Decrypt Conti ransomware with new Kaspersky solution?
Decrypting Conti ransomware with the new Kaspersky solution is a relatively straightforward process. Here's what you need to do:
1. Download the latest version of the free RakhniDecryptor tool from the Kaspersky website.
2. Install the RakhniDecryptor tool on your computer.
3. Launch the RakhniDecryptor tool and click on the "Change parameters" button.
4. In the "Select action" section, choose "Decrypt files".
5. In the "Select an encrypted file" section, click on the "Browse" button and select the encrypted file that you want to decrypt.
6. In the "Select ransom note" section, click on the "Browse" button and select the ransom note that was left by the Conti ransomware.
7. In the "Select original file" section, click on the "Browse" button and select an original version of the encrypted file that has not been encrypted by the Conti ransomware.
8. In the "Additional actions" section, you can choose to delete the encrypted files after decryption or overwrite them with the decrypted files.
9. Click on the "Start" button to begin the decryption process.
The RakhniDecryptor tool will use the private keys and decryption code that Kaspersky has obtained to decrypt your files. If the tool is able to successfully decrypt your files, you should be able to access them again without any issues. However, it's important to note that not all files may be recoverable, especially if they have been damaged or corrupted during the encryption process.
text-davinci-002-render-sha