Prometheus ransomware Decryptor for free


ransomware decrypt,Prometheus ransomware,malware removal,ransomware removal,ransomware,CyCraft decryptor, tik tok

Taiwanese security company CyCraft has released a free app that can help Prometheus ransomware victims recover and decrypt their files.


The decryption works effectively by forcing the encryption key used to lock the victim's data, and it is available for free on GitHub.


"As known Prometheus uses Salsa20 ransomware with a random hash count-based password to encrypt Fireworks. The size of the random password is 32 bytes, and each character is a visible character. Since the password uses the tickcount number as the key, we can brutally guess it,” CyCraft Team wrote in a blog post at the beginning of the month.


The only downside to CyCraft decryption is that it can only handle brute force pressing of the decryption key from small files only.


The decryption was released on July 13, and this was also the last date that the Prometheus gang posted any content on the dark web leak site. After two and a half weeks, the Prometheus gang appears to be out of action.


The gang was first spotted in February of this year, and had previously listed more than 40 victims on its leak site. She drew some attention to herself by claiming an association with the more notorious REvil gang, which they removed after the REvil gang's attack on Kaseya.


In fact, on the other hand, the two ransomware strains couldn't be more different. REvil was an advanced piece of C++ malware, while Prometheus was based on the leaked code of Thanos ransomware, encoded in C#.

Prometheus ransomware,malware removal, ransomware removal, ransomware, ransomware decrypt, CyCraft decryptor

Soon after Prometheus fell silent, a new group called Aaron, also operating at the head of Thanos' code base, began the attacks, leading some experts to believe that Prometheus' operators renamed them Aaron.


Emsisoft did not rule out that the company will eventually create a decryption tool for Prometheus and other Thanos strains that can also recover large files. If they do, the application will be made available on the company's website and NoMoreRansom portal for free.


Since Thanos-based ransomware strains are causing new victims on a weekly basis, this could be sooner rather than later.

Next Post Previous Post