SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Ryuk Ransomware Decryptor Is Broken, Could Lead to Data Loss
Date    Wednesday December 11 2019, @03:04AM
Author    Fnord666
Topic   
from the program-is-borked dept.
https://soylentnews.org/article.pl?sid=19/12/10/0349232

upstart writes:

Submitted via IRC for chromas

Ryuk Ransomware Decryptor Is Broken, Could Lead to Data Loss

Due to recent changes in the Ryuk Ransomware encryption process, a bug in the decryptor could lead to data loss in large files.

Ryuk is a ransomware infection known to target the enterprise or govt agencies by gaining access to their networks and then encrypting as many computers as possible. The attackers then demand large ransoms, sometimes in the millions, in order to receive a decryptor for their files.

According to antivirus and security firm Emsisoft, Ryuk was recently modified so that it does not encrypt the entire file if it is larger than than 57,000,000 bytes or 54.4 megabytes. This is done to prevent the encryption process from taking too long, which could allow victims to more readily detect that the ransomware was running.

Instead the decryptor will partially encrypt the file by encrypting a certain number of 1,000,000 byte blocks of data, up to a hard maximum of 2,000

For a large file, the ransomware will then store the number of blocks that were encrypted next the 'HERMES' file marker in the footer. For example, the encrypted file below had 112 1 million-byte blocks encrypted.

Smaller files that are entirely encrypted, though, will not contain a block count in the footer.

Emsisoft CTO Fabian Wosar told BleepingComputer that a bug in the Ryuk decryptor is causing the size of the footer in large files to not be properly calculated due to the variable nature of the block count.

This causes the decryptor to truncate certain files before the last byte.


Original Submission

Links

  1. "upstart" - https://soylentnews.org/~upstart/
  2. "Ryuk Ransomware Decryptor Is Broken, Could Lead to Data Loss" - https://www.bleepingcomputer.com/news/security/ryuk-ransomware-decryptor-is-broken-could-lead-to-data-loss/
  3. "known to target theĀ enterprise" - https://www.bleepingcomputer.com/news/security/ryuk-ransomware-is-making-victims-left-and-right/
  4. "Emsisoft" - https://blog.emsisoft.com/en/35023/bug-in-latest-ryuk-decryptor-may-cause-data-loss/
  5. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=37997

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Ryuk Ransomware Decryptor Is Broken, Could Lead to Data Loss on 2024-04-25 06:46:17