Emsisoft releases new decryptor for Ziggy ransomware
#1
Exclamation 
Quote:
[Image: Ziggy-Decryptor.png]

We just released a new free decryption tool for Ziggy ransomware.  

If you have been infected with this ransomware, please download the free decryption tool linked below and DO NOT PAY the ransom. A detailed guide is also included. 

Download the Ziggy decryptor here

Ziggy announces retirement

In early February 2021, the Ziggy group announced via Telegram that they would be shutting down their ransomware operation and releasing victims’ decryption keys.  

The group’s early retirement was apparently motivated by guilt and fear of legal repercussion. Speaking with BleepingComputer, an administrator for the Ziggy group said that they felt guilty about their actions and expressed concerns over global law enforcement efforts, which recently saw charges brought against Emotet and Netwalker affiliates. 

Following the announcement, the Ziggy ransomware admin released an SQL file containing 922 decryption keys, 340 of which are unique IDs. We can confirm that the keys are legitimate.  

Emsisoft releases Ziggy decryption tool

The admin also released a decryptor that victims of Ziggy can use with the decryption keys listed in the SQL file. However, the decryptor is cumbersome to use and crashes frequently. We strongly recommend that victims use our decryptor instead of the attacker-provided decryptor

The Emsisoft decryptor is simple to use and requires just one encrypted file and an Internet connection. The decryptor then pulls decryption keys from our server based on the victim’s ID, and also the offline keys. Victim IDs are based on the volume serial of the C: drive of the infected machine.  

Download the Emsisoft Ziggy decryptor here.

Technical details

Ziggy is a strain of ransomware that encrypts a victim’s files and demands a ransom payment to restore access. It primarily targets businesses and has impacted at least 340 unique victims since it was first observed in November 2020.  

Encrypted files are appended with the .ziggy extension, and a ransom note containing communication and payment instructions is displayed on the victim’s desktop. 

Ransom note sample:  
 
Quote:All your files have been encrypted!
Ziggy Ransomware 
All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail: [REDACTED]
Write this ID in the title of your message : [REDACTED]
In case of no answer in 12 hours write us to this e-mail: [REDACTED]
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the tool that will decrypt all your files.
Free decryption as guarantee
Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 4Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)
How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click ‘Buy bitcoins’, and select the seller by payment method and price.
https://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
http://www.coindesk.com/information/how-...-bitcoins/
Attention!
# Do not rename encrypted files.
# Do not try to decrypt your data using third party software, it may cause permanent data loss.
# Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Intel shares Granite Rapids-WS Xeon 600 ...
Intel posts Xeon 6...harlan4096 — 09:49
Manjaro Linux 26.0.3 Build 260228
Manjaro Linux 26.0...harlan4096 — 08:20
K-Lite Codec Pack 19.5.0 / 19.5.4 Update
Changes in 19.5.4 ...harlan4096 — 08:19
JEDEC publishes UFS 5.0 spec with up to ...
KIOXIA starts samp...harlan4096 — 08:17
QOwnNotes
26.2.15  Fix Qt5 ...Kool — 07:30

[-]
Birthdays
Today's Birthdays
avatar (51)Claudestync
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
There are no staff members currently online.

>