Emsisoft releases a new decryptor for Hakbit ransomware
#1
Exclamation 
Quote:
[Image: logo.svg]

We just released a new free decryption tool for the Hakbit ransomware strain. Hakbit has multiple confirmed victims, including home users and businesses in the United States and Europe.

While ransom notes are usually text files, Hakbit demands are displayed by changing the victim’s desktop wallpaper. Possibly uniquely, the wallpaper includes a QR code that points to the attackers’ Bitcoin address.

You can download the FREE decryption tool linked below. A detailed guide is also included.

Download the Hakbit Decryptor here

Technical details

Hakbit encrypts its victims’ files using AES-256 and appends with the extension “.crypted”. On installation, Hakbit attempts to conceal its presence by randomly naming its executable to one of the following: lsass.exe, svchst.exe, crcss.exe, chrome32.exe, firefox.exe, calc.exe, mysqld.exe, dllhst.exe, opera32.exe, memop.exe, spoolcv.exe, ctfmom.exe, or SkypeApp.exe.

The ransom note reads:

Quote:Atention! all your important files were encrypted!
to get your files back send 300 USD worth in Bitcoins and contact us with proof of
payment and your Unique Identifier Key.
We will send you a decryption tool with your personal decryption password.

Where can you buy Bitcoins:

https://www.coinbase.com
https://localbitcoins.com

Contact: hakbit@protonmail.com.

Bitcoin wallet to make the transfer to is: 12grtxACJZkgT2nGAvMesgoM4ADHJ6NTaW
Unique Identifier Key (must be sent to us together with proof of payment):
Number of files that you could have potentially lost forever can be as high as: 3396
...
Continue Reading
Reply


Messages In This Thread
Emsisoft releases a new decryptor for Hakbit ransomware - by harlan4096 - 22 November 19, 08:47

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AdGuard Browser Extension 5.2.77
More information a...harlan4096 — 07:00
Microsoft Edge Version 140.0.3485.81
ersion 140.0.3485....harlan4096 — 06:55
Vivaldi 7.6 Build 3797.55
Vivaldi 7.6 Build ...harlan4096 — 06:54
Virtual-machine escape – in a Spectre v2...
A fresh research p...harlan4096 — 06:53
Windows 11 is getting a video wallpaper ...
Microsoft is testi...harlan4096 — 06:51

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (38)eqiduseb
avatar (40)maskbSleew

[-]
Online Staff
There are no staff members currently online.

>