Categories: Security

Security Firms And Police Fight Back Against Ransomware

Two IT security firms have joined with the Dutch National Police and Europol to launch a website aimed at combating the rapidly growing problem of ransomware.

Kaspersky Lab and Intel said the No More Ransom site is intended to bring together law enforcement and private-sector resources to take aim at the issue, and is open to new members.

Decryption keys

Some ransomware decryption keys have been obtained by security experts and No More Ransom makes these available in the form of four decryption tools, the most recent of which was developed in June for the Shade variant after Shade’s control servers were seized, Kaspersky said.

Shade was involved in infections in Russia, Ukraine, Germany, Austria and Kazakhstan and the variant was also found in France, the Czech Republic, Italy and the US, according to the firm.

The site also provides the means for the public to report ransomware cases.

The site’s backers said it is intended to help coordinate the fight against ransomware, which has grown so rapidly in part because those affected are prepared to pay.

“The appearance of decryption tools is just the first step on this road,” stated Kaspersky Lab researcher Jornt van der Wiel. “Soon there will be many more companies and law enforcement agencies from other countries and regions fighting ransomware together.”

Growing threat

The project said it is looking for keys for some of the most prevalent variants, including Locky, Cryptolocker, Teslacrypt and Torrentlocker.

Industry observers have warned that ransomware, which typically encrypts a user’s files and demands payment to decode them, is spreading rapidly as criminals find it a reliable source of revenues.

Kaspersky said the number of cases it tracked rose more than five times from 2015 to 2016, with more than 700,000 attacks recorded last year.

A recent study by security experts found that ransomware gangs have developed sophisticated and friendly customer service operations aimed at gaining the confidence of those attacked and ensuring they deliver payment.

Users are advised to avoid the threat by frequently backing up their systems and avoiding opening attachments from unknown parties.

In cases where decryption keys have been made available the affected files can be recovered, but otherwise users have little choice but to pay the ransom or lose access to their data.

Quiz: What do you know about cybersecurity in 2016?

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Google Consolidates DeepMind And AI Research Teams

AI push sees Alphabet's Google saying it will consolidate its AI teams in its Research…

15 hours ago

Apple Pulls WhatsApp, Threads From China App Store

Beijing orders Apple to pull Meta's WhatsApp and Threads from its Chinese App Store over…

18 hours ago

Intel Foundry Assembles Next Gen Chip Machine From ASML

Key milestone sees Intel Foundry assemble ASML's new “High NA EUV” lithography tool, to begin…

22 hours ago

Creating Deepfake Porn Without Consent To Become A Crime

People who create sexually explicit ‘deepfakes’ of adults will face prosecution under a new law…

2 days ago

Google Fires 28 Staff Over Israel Protest, Undertakes More Layoffs

Protest at cloud contract with Israel results in staff firings, in addition to layoffs of…

2 days ago