Author

Topic: Hacking Gone Wrong: Ryuk Ransomware decryptor damages larger files, even if you (Read 161 times)

legendary
Activity: 3668
Merit: 6382
Looking for campaign manager? Contact icopress!
I don't think anyone is that stupid of not to have a back up so, nothing lost literally but working hours I guess.

You'd be surprised. The more important the state institution is, the better the chance the (person paid as) sysadmin doesn't know or doesn't care about backups.
I've read of hospitals and I think police departments too having difficulties in the past because of ransomware.
legendary
Activity: 2464
Merit: 3878
Hire Bitcointalk Camp. Manager @ r7promotions.com
Not aware about the full story and it's not that I am interyat all but this just popped in mind : There are always has an easy with to save copy of digital files.

I don't think anyone is that stupid of not to have a back up so, nothing lost literally but working hours I guess.
hero member
Activity: 2632
Merit: 833
As reported by security firm Emisoft;

Quote
In one of the latest versions of Ryuk, changes were made to the way the length of the footer is calculated. As a result, the decryptor provided by the Ryuk authors will truncate files, cutting off one too many bytes in the process of decrypting the file. Depending on the exact file type, this may or may not cause major issues. In the best-case scenario, the byte that was cut off by the buggy decryptor was unused and just some slack space at the end created by aligning the file towards certain file size boundaries. However, a lot of virtual disk type files like VHD/VHDX as well as a lot of database files like Oracle database files will store important information in that last byte and files damaged this way will fail to load properly after they are decrypted.

https://blog.emsisoft.com/en/35023/bug-in-latest-ryuk-decryptor-may-cause-data-loss/

I guess hackers can sometimes be dumb, lol. However, the only real victims here are those who have paid the ransom in hope that their files will be decrypted. But it's not the case, the good thing is, Emisoft is there to help out.

Disclaimer: I'm not an affiliate of Emisoft, just that this news gives me a good chuckle about the hackers Grin
Jump to: