Free Key Group ransomware decryptor helps victims recover data (www.bleepingcomputer.com)
from IllNess@infosec.pub to securitynews@infosec.pub on 31 Aug 2023 19:18
https://infosec.pub/post/2038837

Direct link to report which has the decryptor written in Python:

Decrypting Key Group Ransomware: Emerging Financially Motivated Cyber Crime Gang (blog.eclecticiq.com)

threaded - newest

IllNess@infosec.pub on 31 Aug 2023 19:19 next collapse

If anyone had the unfortunate experience needing to use this, please let me know how quick the script is. It looks fairly slow.

Ubermeisters@lemmy.zip on 31 Aug 2023 23:06 next collapse

I’m not clear on the specifics but I’ve FWD’d this to someone I know in this exact scenario currently. Unsure if it’s the same Russian group, or if this is “breaking news” or not (aka if friends have already seen this decrypt solution before this article posted today), but this could make a huge difference to someone out there, even if not them. Thanks for posting.

happyloaf@infosec.pub on 02 Sep 2023 11:41 collapse

You could re-implement this mult-threaded etc if you liked

scrubbles@poptalk.scrubbles.tech on 02 Sep 2023 21:27 collapse

Coming tomorrow, new version with a new password