The fake decryption tool will actually double-encrypt compromised files, making a bad problem even worse.
Hackers can be real jerks.
A new form of malware has been developed to imitate decryption software that is supposed to help people who have already been victims of ransomware encryption attacks.
According to a new report from Bleeping Computer, the ransomware--which claims to decrypt files affected by the ‘STOP Djvu’ ransomware--actually double-encrypts files, making victims’ problems even worse. The virus, called “Zorab”, was discovered by Michael Gillespie, the creator of the ID Ransomware service.
Zorab compounds existing problems
Imagine: for years, encrypting ransomware has been a nightmare scenario for unwitting computer users. They click the wrong link, or open the wrong email, and suddenly find themselves in a situation in which all of their files--their most precious photos, the novels they’ve been working on, their musical projects, their work--is encrypted; the ransomware claims that only way to decrypt it is to pay a huge fee.
Of course, there have been anti-malware tools that have been developed to decrypt files without paying exorbitant amounts of money: this is exactly what this new malware is imitating. It claims to help victims of ransomware decrypt their files for free, and then double-encrypts them.
Indeed, when the victim downloads opens one of these fake decryption “tools” and clicks on “Start Scan,” the software extracts an executable file called crab.exe--the Zorab ransomware itself. Once executed, the tool will encrypt all files present on the device with a .ZRB extension.
Zorab also creates ransom notes named '--DECRYPT--ZORAB.txt.ZRB' that are present in each of the folders it encrypts; this note contains instructions on how to contact the ransomware operators for payment instructions.
"We absolutely do not care about you and your deals, except getting benefits," the notes read.
STOP may be the most prolific ransomware out there; Zorab aims to take advantage of this
In a way, the creators of Zorab were quite clever: STOP Dvju is thought to be one of the most prolific--if not the most prolific--pieces of ransomware on the books. Therefore, creating a fake decryption tool for STOP is a quick and easy way to spread another piece of ransomware.
While it hasn’t gotten as much media attention as other pieces ransomware that targets high-net-worth individuals and organizations (such as Maze, REvil, Netwalker, and DoppelPaymer), there are roughly 600 STOP ransomware submissions a day to the ID-Ransomware ransomware identification service.
Bleeping Computer described STOP as “the most actively distributed ransomware over the past year.”
The publication also said that Zorab is currently being analyzed, and that victims should not pay the ransoms that are being demanded of them until it is confirmed that there is no way to exploit weaknesses in Zorab’s software.
Hackers can be real jerks.
A new form of malware has been developed to imitate decryption software that is supposed to help people who have already been victims of ransomware encryption attacks.
According to a new report from Bleeping Computer, the ransomware--which claims to decrypt files affected by the ‘STOP Djvu’ ransomware--actually double-encrypts files, making victims’ problems even worse. The virus, called “Zorab”, was discovered by Michael Gillespie, the creator of the ID Ransomware service.
Zorab compounds existing problems
Imagine: for years, encrypting ransomware has been a nightmare scenario for unwitting computer users. They click the wrong link, or open the wrong email, and suddenly find themselves in a situation in which all of their files--their most precious photos, the novels they’ve been working on, their musical projects, their work--is encrypted; the ransomware claims that only way to decrypt it is to pay a huge fee.
Of course, there have been anti-malware tools that have been developed to decrypt files without paying exorbitant amounts of money: this is exactly what this new malware is imitating. It claims to help victims of ransomware decrypt their files for free, and then double-encrypts them.
Indeed, when the victim downloads opens one of these fake decryption “tools” and clicks on “Start Scan,” the software extracts an executable file called crab.exe--the Zorab ransomware itself. Once executed, the tool will encrypt all files present on the device with a .ZRB extension.
Zorab also creates ransom notes named '--DECRYPT--ZORAB.txt.ZRB' that are present in each of the folders it encrypts; this note contains instructions on how to contact the ransomware operators for payment instructions.
"We absolutely do not care about you and your deals, except getting benefits," the notes read.
STOP may be the most prolific ransomware out there; Zorab aims to take advantage of this
In a way, the creators of Zorab were quite clever: STOP Dvju is thought to be one of the most prolific--if not the most prolific--pieces of ransomware on the books. Therefore, creating a fake decryption tool for STOP is a quick and easy way to spread another piece of ransomware.
While it hasn’t gotten as much media attention as other pieces ransomware that targets high-net-worth individuals and organizations (such as Maze, REvil, Netwalker, and DoppelPaymer), there are roughly 600 STOP ransomware submissions a day to the ID-Ransomware ransomware identification service.
Bleeping Computer described STOP as “the most actively distributed ransomware over the past year.”
The publication also said that Zorab is currently being analyzed, and that victims should not pay the ransoms that are being demanded of them until it is confirmed that there is no way to exploit weaknesses in Zorab’s software.
Rachel is a self-taught crypto geek and a passionate writer. She believes in the power that the written word has to educate, connect and empower individuals to make positive and powerful financial choices. She is the Podcast Host and a Cryptocurrency Editor at Finance Magnates.
FM's Editor-in-Chief Yam Yehoshua on how the newsroom evaluates stories.
FM's Editor-in-Chief Yam Yehoshua on how the newsroom evaluates stories.
FM's Editor-in-Chief Yam Yehoshua on how the newsroom evaluates stories.
FM's Editor-in-Chief Yam Yehoshua on how the newsroom evaluates stories.
Matthew Smith, Group CEO at EC Markets, speaking at FMLS:24
Matthew Smith, Group CEO at EC Markets, speaking at FMLS:24
Matthew Smith, Group CEO at EC Markets, speaking at FMLS:24
Matthew Smith, Group CEO at EC Markets, speaking at FMLS:24
Finance Magnates Annual Awards 2024 | FM Awards 2024 Highlights
Finance Magnates Annual Awards 2024 | FM Awards 2024 Highlights
🎥Catch the best moments from the Finance Magnates Annual Awards Gala Dinner!
An evening where top names in finance came together to celebrate achievements, enjoy live music, and connect over a memorable dinner. Watch the highlights and feel the energy of our first gala in Cyprus!
Congratulations to all the winners for their dedication to excellence and leadership in the financial industry, including XM, Trading PRO, FP Markets, Deriv, FxPro, LATAM, Headway, ATFX, FBS, AMEGA, EC Markets, Axi
For more information about the 1st Finance Magnates Annual Awards, visit https://bit.ly/3Zb7wNz
#FinanceMagnatesGala #IndustryExcellence #GalaHighlights #FinanceMagnatesAnnualAwards #FinanceMagnatesAwards #CelebratingSuccess #FinanceCommunity
🎥Catch the best moments from the Finance Magnates Annual Awards Gala Dinner!
An evening where top names in finance came together to celebrate achievements, enjoy live music, and connect over a memorable dinner. Watch the highlights and feel the energy of our first gala in Cyprus!
Congratulations to all the winners for their dedication to excellence and leadership in the financial industry, including XM, Trading PRO, FP Markets, Deriv, FxPro, LATAM, Headway, ATFX, FBS, AMEGA, EC Markets, Axi
For more information about the 1st Finance Magnates Annual Awards, visit https://bit.ly/3Zb7wNz
#FinanceMagnatesGala #IndustryExcellence #GalaHighlights #FinanceMagnatesAnnualAwards #FinanceMagnatesAwards #CelebratingSuccess #FinanceCommunity
FMLS:24 | Shaping the Next Era of Financial Evolution
FMLS:24 | Shaping the Next Era of Financial Evolution
Welcome to FMLS:24 – the premier event where influential brands and leaders in trading, payments, fintech, and digital assets come together!
Join over 2,500 industry professionals, engage with 150+ expert speakers, and discover endless opportunities with 70+ top exhibitors. FMLS:24 is where senior executives and decision-makers gather to close deals, forge new partnerships, and strengthen connections with long-term clients.
Whether you’re in finance, technology, or payments, this summit is your gateway to future growth, meaningful collaborations, and industry-leading insights.
👉 Don't miss out – secure your ticket now at https://events.financemagnates.com/ZQEYy0?utm_source=youtube&utm_campaign=fmls24-awareness&utm_medium=video&RefId=MLS%3A24+Video+Promo
#fmls #fmls24 #fmevents #financemagnates #forex #payments #crypto #events #london #fintech #ai #generativeai #technology #onlinetrading #forex #investing #investors #tech
📣 Stay updated with the latest in finance and trading!
Follow FMevents across our social media platforms for news, insights, and event updates. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/showcase/financemagnates-events/
👍 Facebook: https://www.facebook.com/FinanceMagnatesEvents
📸 Instagram: https://www.instagram.com/fmevents_official
🐦 Twitter: https://twitter.com/F_M_events
🎥 TikTok: https://www.tiktok.com/@fmevents_official
▶️ YouTube: https://www.youtube.com/@FinanceMagnates_official
Don't miss out on our latest videos, interviews, and event coverage. Subscribe to our YouTube channel for more!
Welcome to FMLS:24 – the premier event where influential brands and leaders in trading, payments, fintech, and digital assets come together!
Join over 2,500 industry professionals, engage with 150+ expert speakers, and discover endless opportunities with 70+ top exhibitors. FMLS:24 is where senior executives and decision-makers gather to close deals, forge new partnerships, and strengthen connections with long-term clients.
Whether you’re in finance, technology, or payments, this summit is your gateway to future growth, meaningful collaborations, and industry-leading insights.
👉 Don't miss out – secure your ticket now at https://events.financemagnates.com/ZQEYy0?utm_source=youtube&utm_campaign=fmls24-awareness&utm_medium=video&RefId=MLS%3A24+Video+Promo
#fmls #fmls24 #fmevents #financemagnates #forex #payments #crypto #events #london #fintech #ai #generativeai #technology #onlinetrading #forex #investing #investors #tech
📣 Stay updated with the latest in finance and trading!
Follow FMevents across our social media platforms for news, insights, and event updates. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/showcase/financemagnates-events/
👍 Facebook: https://www.facebook.com/FinanceMagnatesEvents
📸 Instagram: https://www.instagram.com/fmevents_official
🐦 Twitter: https://twitter.com/F_M_events
🎥 TikTok: https://www.tiktok.com/@fmevents_official
▶️ YouTube: https://www.youtube.com/@FinanceMagnates_official
Don't miss out on our latest videos, interviews, and event coverage. Subscribe to our YouTube channel for more!