The creator of the ransomware ransomware Ziggi published encryption keys to decrypt infected files. Security researcher M. Shahpasandi told BleepingComputer that the administrator of the ransomware Ziggy announced on Telegram that they would cease their work and release all decryption keys.
The hacker explained his actions with fears due to the recent arrest of the developers of ransomware
Emotet and
Netwalker, as well as guilt. Also, the administrator of Ziggy ransomware published a SQL file containing 922 decryption keys. For each victim, the SQL file contains three keys required to decrypt the encrypted files.
The ransomware administrator also posted a
VirusTotal decryptor that victims can use with the keys listed in the SQL file and shared the source code of the offline decryption program with Emsisoft
Using the released keys, expert Michael Gillespie created a decryptor for the Ziggy ransomware you can download the program here
https://www.emsisoft.com/ransomware-decryption-tools/ziggyWhile the administrator of the ransomware appears to be honest about his intention to close and release the keys, BleepingComputer suggests using the security company's decoder rather than the one supplied by the threat actor. Be careful with network security