Security News > 2021 > August > Decryption Key for Ransomware Delivered via Kaseya Attack Made Public

Decryption Key for Ransomware Delivered via Kaseya Attack Made Public
2021-08-11 14:39

A key that can be used to decrypt files encrypted by the REvil ransomware delivered as part of the Kaseya attack has been made public.

According to threat intelligence company Flashpoint, an individual using the online moniker "Ekranoplan" recently claimed on a hacker forum that they had obtained a decryption key for the REvil ransomware.

Flashpoint has tested the leaked key and confirmed that it can be used by victims of the Kaseya attack to recover files encrypted by the ransomware.

Several people have confirmed on Twitter that the key works for decrypting files encrypted by the REvil variant used in the Kaseya attack.

While the decryption key might still be useful to some victims, organizations hit by the Kaseya attack should have received a universal decryptor from Kaseya itself last month.

The individuals behind the attack initially offered a universal decryptor that could be used by all Kaseya victims for $70 million, and the amount was later reportedly brought down to $50 million.


News URL

http://feedproxy.google.com/~r/securityweek/~3/7XWl4ZdNOGw/decryption-key-ransomware-delivered-kaseya-attack-made-public

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Kaseya 6 0 5 14 13 32