Rival gang leaks decryption keys for Chimera ransomware

The authors of the Petya and Mischa ransomware programs leaked around 3,500 decryption keys for the Chimera ransomware

Aside from the efforts of security researchers and antivirus companies, malware victims can sometimes also benefit from the fighting between rival cybercriminal groups.

That happened this week when the creators of the Petya and Mischa ransomware programs leaked about 3,500 RSA private keys allegedly corresponding to systems infected with Chimera, another ransomware application.

In a post Tuesday on Pastebin, Mischa's developers claimed that earlier this year they got access to big parts of the development system used by Chimera's creators.

As a result of that hack, they obtained the source code for Chimera and integrated some of it into their own ransomware project, according to the Pastebin message.

This had already been confirmed by researchers from Malwarebytes, who reported last month that Mischa shares some components with Chimera.

There's no confirmation yet that the newly leaked RSA keys actually work to decrypt files affected by Chimera, but there's a big chance that they're legitimate.

"Checking if the keys are authentic and writing a decryptor will take some time – but if you are a victim of Chimera, please don’t delete your encrypted files, because there is a hope that soon you can get your data back," the Malwarebytes researchers said Tuesday in a blog post.

The Chimera ransomware program appeared in November and stood out because it threatened to leak users files on the internet in addition to encrypting them if they didn't pay up. There's no evidence its creators actually delivered on this threat and it was most likely intended as an intimidation tactic to increase the chance that victims will pay.

Mischa, on the other hand, is a newer threat. It first appeared in May and is typically bundled with another ransomware program, called Petya, that encrypts the master file table (MFT) of hard disk drives.

Since Petya's form of encryption requires admin access, Mischa is used as a backup when the needed privileges cannot be obtained. Mischa acts like most other ransomware programs, encrypting the victim's files directly.

Also on Tuesday, Petya and Mischa's creators launched an affiliate system, essentially turning their malware combo into ransomware as a service. This means other cybercriminals can now sign up to distribute these malicious programs for a portion of the profits.

"Unfortunately, this will most likely lead to a greater amount of distribution campaigns for this ransomware," said Lawrence Abrams, the founder of tech support forum BleepingComputer.com, in a blog post.

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Essentials

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?