Kaspersky Labs has updated their ransomware decryptor tool to include Jaff ransomware (v1.21.2.1). This is great news for those who have become a victim of Jaff and are wondering if they must pay the hefty ransom (thousands of dollars’ worth of bitcoin). This free tool, from one of the top anti-malware companies, is available at https://support.kaspersky.com/viruses/disinfection/10556
Back in May, the Jaff ransomware was spreading at a rate of 5 million per hour. It is similar to the Locky variant but has a higher ransom. Infection occurs via a malicious email attachment, usually a PDF document, that opens an embedded Microsoft Word file containing a macro script. This macro, if allowed to run, downloads and executes the payload.
The Rakhni Decryptor can be used to decrypt files that have been altered by the following types of ransomware variants:
The detailed instructions are on the site. It is somewhat technical, so take your time and do it right. This may be your only opportunity to recover your files without paying your attackers.
Prevention is better than a cure. To avoid Jaff and others like it, follow these three steps:
For cures to other ransomware variants, check out the free tools at nomoreransom.org provided by industry leading cybersecurity software companies.
Interested in more? Follow me on LinkedIn, Twitter (@Matt_Rosenquist), Information Security Strategy, and Steemit to hear insights and what is going on in cybersecurity.