itb-nz logo
Story image

Cisco Talos releases PyLocky ransomware decryptor - but there's a catch

14 Jan 2019

Security firm Cisco Talos has released a free decryption tool for Windows users affected by the PyLocky ransomware – but it won’t work for everyone.

PyLocky is an imitation of the notorious ‘Locky’ ransomware, except it is written in a programming language called Python. The ransomware tries to mimic other ransomware families. While ransomware is a menace to those who happen to be infected by it, decryption tools can often reverse the damage. In PyLocky’s case Cisco Talos managed to create a decryption tool, but there’s a very big catch.

The tool will only work for those who managed to capture a PCAP of the outbound connection attempt to the ransomware’s command & control servers – a connection that happens mere seconds after the infection. In a nutshell, the PyLocky ransomware decryptor will only work on machines that have network traffic monitoring capabilities.

According to Cisco Talos, PyLocky generates a random user ID and password when it executes. It also gathers information about the infected machine by using WMI wrappers.

"After obtaining the absolute path of every file on the system, the malware then calls the encryption algorithm, passing it the IV and password.”

Each file is first base64-encoded before it is encrypted. The malware appends the extension ".lockedfile" to each file it encrypts - for example, the file "picture.jpg" would become "picture.jpg.lockedfile." 

Each file is then overwritten with a ransom demand.

For those victims who do use network monitoring software, they just need to download the decryptor to their infected machine, download WinPcap, specify the PCAP file with IV and password, and wait for the decryptor to do its thing. The company says that during its testing phase, the decryptor was able to recover three infected systems, however very large files 4GB and over may not be able to be decrypted.

The company says the decryptor is built for use on Windows systems and takes no responsibility for misuse of the decryptor tool.

“Talos encourages users never to pay an attacker-demanded ransom, as this rarely results in the recovery of encrypted files. Rather, victims of this ransomware should restore from backups if their files cannot be decrypted. Just as in the June 2017 Nyetya attack, Talos has observed on numerous occasions that attackers who are demanding ransoms may have no way to communicate with victims to provide a decryptor,” says Cisco Talos.  

Story image
Blue Prism extends human-to-digital worker collaboration with new Interact capability
Blue Prism Interact is a human-to-digital worker collaboration capability that enables employees to team up with digital workers to initiate, instruct, verify, receive, and authorise a variety of business processes through the digital workforce.More
Link image
Data is an organisation's most significant asset - here's how to protect it
Data resilience strategies are becoming more crucial as more value is ascribed to a company's data. If it's not stored securely and cost-effectively, expect problems.More
Story image
Video: 10 Minute IT Jams - Who is Enlighten Designs?
Today, Techday speaks to Enlighten Designs founder and CEO Damon Kelly, who discusses the company's business journey, a recently signed partnership with an Australian digital services provider, and its vision for the future of web design.More
Story image
Commerce Commission tells telcos to improve consumer choice
Mobile operators should improve consumer choice through easier comparisons.More
Story image
From 1G to 5G: How innovations in cellular have shaped our lives
As we look to the present decade from 2020 onwards, 5G will be at the forefront. The race for 5G is not about merely deploying new infrastructure, but getting the first-mover advantage in who can build and take the leadership role in the host of new applications and services that 5G will enable.More
Link image
Webinar: Best practices for keeping your video chats secure
Video collaboration providers nowadays operate exclusively on a multi-tenant, public cloud - and security and privacy concerns have come into the spotlight. Here's how to secure your communications.More