{"id":23548,"date":"2022-03-06T00:01:00","date_gmt":"2022-03-05T23:01:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=23548"},"modified":"2022-03-05T02:31:09","modified_gmt":"2022-03-05T01:31:09","slug":"hermeticransom-ransomware-decryptor-verfgbar","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/03\/06\/hermeticransom-ransomware-decryptor-verfgbar\/","title":{"rendered":"HermeticRansom Ransomware Decryptor available"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/?p=263142\" target=\"_blank\" rel=\"noopener\">German<\/a>]Security researchers have released a free decryptor for HermeticRansom ransomware. Thanks to bugs in the cryptography algorithm, it was possible to develop this decryptor. Victims can decrypt files of this ransomware, which is especially widespread in Ukraine.<\/p>\n<p><!--more--><\/p>\n<p>Nicolas Karassas points out the release of the decryptor and <a href=\"https:\/\/threatpost.com\/free-hermeticransom-ransomware-decryptor-released\/178762\/\" target=\"_blank\" rel=\"noopener\">this ThreadPost article<\/a> with a description of the details in the following <a href=\"https:\/\/twitter.com\/Dinosn\/status\/1499792572046360580\" target=\"_blank\" rel=\"noopener\">tweet<\/a>.&nbsp; <\/p>\n<p><a href=\"https:\/\/twitter.com\/Dinosn\/status\/1499792572046360580\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"HermeticRansom Ransomware Decryptor \" alt=\"HermeticRansom Ransomware Decryptor \" src=\"https:\/\/i.imgur.com\/TJtY4OW.png\"><\/a><\/p>\n<p>The free decrypter is able to decrypt files encrypted by ransomware found piggybacking with HermeticWiper malware. This was detected by <a href=\"https:\/\/twitter.com\/ESETresearch\/status\/1496581903205511181\" target=\"_blank\" rel=\"noopener\">ESET<\/a> and <a href=\"https:\/\/twitter.com\/threatintel\/status\/1496578746014437376\" target=\"_blank\" rel=\"noopener\">Symantec<\/a> days ago on computers belonging to financial, defense, aerospace and IT service providers in Ukraine, Lithuania and Latvia.<\/p>\n<p>CrowdStrike's intelligence team <a href=\"https:\/\/www.crowdstrike.com\/blog\/how-to-decrypt-the-partyticket-ransomware-targeting-ukraine\/\" target=\"_blank\" rel=\"noopener\">discovered<\/a> a few days ago that HermeticRansom (PartyTicket) had a crackable encryption process so that the decryptor could be developed. The decryptor can be downloaded <a href=\"https:\/\/decoded.avast.io\/threatresearch\/help-for-ukraine-free-decryptor-for-hermeticransom-ransomware\/#howto\" target=\"_blank\" rel=\"noopener\">here<\/a>. More details can be found in the linked article.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Security researchers have released a free decryptor for HermeticRansom ransomware. Thanks to bugs in the cryptography algorithm, it was possible to develop this decryptor. Victims can decrypt files of this ransomware, which is especially widespread in Ukraine.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-23548","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=23548"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23548\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=23548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=23548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=23548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}