Article 52T7W Shade (Troldesh) Ransomware Shuts Down and Releases Decryption Keys

Shade (Troldesh) Ransomware Shuts Down and Releases Decryption Keys

by
martyb
from SoylentNews on (#52T7W)

upstart writes in with an IRC submission for TurkeyWaddle:

Shade (Troldesh) ransomware shuts down and releases decryption keys:

The operators of the Shade (Troldesh) ransomware have shut down over the weekend and, as a sign of goodwill, have released more than 750,000 decryption keys that past victims can now use to decrypt their files.

Security researchers from Kaspersky Lab have confirmed the validity of the leaked keys and are now working on creating a free decryption tool.

[...] The decryption keys released today will help all users who had files encrypted by the Shade ransomware. The keys are believed to account for all versions of the ransomware and all users who ever got infected.

[...] While security experts often recommend saving ransomware-encrypted files on an offline hard drive, most victims simply reinstall their computer from scratch, deleting the encrypted data. Those who saved their encrypted files can now recover data they once considered lost.

The Shade team posted on their GitHub repository:

We are the team which created a trojan-encryptor mostly known as Shade, Troldesh or Encoder.858. In fact, we stopped its distribution in the end of 2019. Now we made a decision to put the last point in this story and to publish all the decryption keys we have (over 750 thousands at all). We are also publishing our decryption soft; we also hope that, having the keys, antivirus companies will issue their own more user-friendly decryption tools. All other data related to our activity (including the source codes of the trojan) was irrevocably destroyed. We apologize to all the victims of the trojan and hope that the keys we published will help them to recover their data.

Original Submission

Read more of this story at SoylentNews.

External Content
Source RSS or Atom Feed
Feed Location https://soylentnews.org/index.rss
Feed Title SoylentNews
Feed Link https://soylentnews.org/
Feed Copyright Copyright 2014, SoylentNews
Reply 0 comments