📜 ⬆️ ⬇️

The creators of the TeslaCrypt Trojan encoder closed the project and published the master key for unlocking



The Bleeping Computer edition reports that the creators of the famous Trojan TeslaCrypt, which encrypted files on the attacked machines, published a master key for unlocking and closed the project.

Initially, TeslaCrypt attacked mainly gamers - the Trojan selected the files associated with a number of popular online games as its targets. The victim was shown a link to the site to receive payment to unlock - the attackers demanded a few hundred dollars. The spread of the virus occurred through compromised websites . In addition, the malware was part of the popular exploit packs Nuclear, Sweet Orange and Angler.
')
According to Bleeping Computer, for the first time, a drop in Trojan activity was noticed by security researchers from Eset. One of them decided to try his luck and contacted TeslaCrypt developer via the support chat on the site for receiving payment, asking to publish the master key for unlocking. To his surprise, he will receive a positive response, and soon the key was really laid out in open access:



Thanks to this, the researcher under the name BloodDolly was able to update the popular unlock utility TeslaDecoder - now the tool can decrypt files blocked by malware version 3.0 and 4.0. This means that all victims of TeslaCrypt, on whose computers the extension files .xxx, .ttt, .micro, .mp3, as well as files without extensions were encrypted, will be able to decrypt them for free. Eset specialists and specialists created their own unblocker.

TeslaCrypt should be replaced by another CryptXXX trojan cryptographer. According to the researchers, there are already cases when sites that previously distributed TeslaCrypt are now installed on CryptXXX users' computers.

Source: https://habr.com/ru/post/301226/


All Articles