In recent months, there has been a considerable increase in the activity of so-called ransomware, a malware variant that encrypts local files on a computer and threatens to destroy them if a ransom is not paid. CoinVault is one of the most damaging recent variants, and in response, Kaspersky has put online its Ransomware Decryptor, a tool with thousands of keys that can get more than one infected user out of trouble.
PC Magazine reported last week that the Lincoln County Sheriff's Office in the state of Maine was forced to pay a $300 ransom to recover its files. The attack was caused by a ransomware called "Megacode", and due to the sensitivity of the data, the police had no choice but to give in to the virtual kidnapper. Something similar happened in November 2013, when the Swansea police department became another victim of the famous CryptoLocker, and in that case, the payment was $750.
Needless to say, ransomware has become one of the most serious threats of recent times. This type of attack makes no distinction between individuals, companies, and security agencies, and each new version is more sophisticated than the previous one.
One of the most recent variants is CoinVault, which increases the ransom price every time its counter reaches zero. Thanks to a new combined effort, it is now possible to recover files affected by CoinVault without paying. The Dutch police obtained a significant number of keys associated with CoinVault attacks, and from that data, Kaspersky created a new tool called Ransomware Decryptor. The decryption process requires some effort on the user's part, but Kaspersky published a PDF document with all the instructions. Basically, you need to enter the Bitcoin wallet address into the database, and if there are linked keys, the next step is to download the tool to free each file.
Kaspersky explains that its tool is a work in progress, and as they discover new keys, they will be added to the database. This makes me think that the people behind CoinVault have already declared their weapon compromised and are pouring their resources into a new version. Once again, this serves to emphasize the user's responsibility when it comes to protecting data. When in doubt, no. Any strange link or email should be ignored and deleted immediately. It's better to lose an opportunity than to invite disaster.