Explorer

Ransomware victim Kaseya gets master key to unlock networks

Boston, Jul 22 (AP): The Florida company whose software was exploited in the devastating Fourth of July weekend ransomware attack, Kaseya, has received a universal key that will decrypt all of the more than 1,000 businesses and public organizations crippled in the global inciden.

Boston, Jul 22 (AP): The Florida company whose software was exploited in the devastating Fourth of July weekend ransomware attack, Kaseya, has received a universal key that will decrypt all of the more than 1,000 businesses and public organizations crippled in the global incident.

Kaseya spokeswoman Dana Liedholm would not say Thursday how the key was obtained or whether a ransom was paid. She said only that it came from a “trusted third party” and that Kaseya was distributing it to all victims.

Ransomware analysts offered multiple possible explanations for why the master key, which can unlock the scrambled data of all the attack's victims, has now appeared. They include: Kaseya paid; a government paid; a number of victims pooled funds; the Kremlin seized the key from the criminals and handed it over through intermediaries — or perhaps the attack's principle protagonist didn't get paid by the gang whose ransomware was used.

The Russia-linked criminal gang whose malware was used in the attack, REvil, disappeared from the internet on July 13. That likely deprived the affiliate that leased REvil's malware of potential income. Affiliates typically earn the lion's share of ransoms. While ransoms as low as USD 45,000 were demanded from smaller victims, the gang was believed to have been overwhelmed by more ransom negotiations than it could manage. It decided to ask USD 50 million to USD 70 million for a master key that would unlock all infections.

By now, many victims will have rebuilt their networks or restored them from backups.

It's a mixed bag, Liedholm said, because some "have been in complete lockdown.” She had no estimate of the cost of the damage and would not comment on whether any lawsuits may have been filed against Kaseya. It is not clear how many victims may have paid ransoms before REvil went dark.

The so-called supply-chain attack of Kaseya was the worst ransomware attack to date because it spread through software that companies known as managed service providers use to administer multiple customer networks, delivering software updates and security patches.

President Joe Biden called his Russian counterpart, Vladimir Putin, afterward to press him to stop providing safe haven for cybercriminals whose costly attacks the U.S. government deems a national security threat. He has threatened to make Russia pay a price for failing to crack down. but has not specified what measure the U.S. may take.

If the universal decryptor for the Kaseya attack was turned over without payment, it would not be the first time ransomware criminals have done that. It happened after the Conti gang hobbled Ireland's national healthcare service in May and the Russian Embassy in Dublin offered “to help with the investigation.” (AP) RS RS

(This story is published as part of the auto-generated syndicate wire feed. No editing has been done in the headline or the body by ABP Live.)

View More
Advertisement
Advertisement
25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Advertisement

Top Headlines

Mumbai: 13 Dead After Ferry Capsizes Near Gateway Of India, 101 Rescued, CM Announces Ex Gratia
Mumbai: 13 Dead After Ferry Capsizes Near Gateway Of India, 101 Rescued, CM Announces Ex Gratia
JPC Constituted On 'One Nation One Election' Bills, Priyanka Gandhi, Anurag Thakur Among Members
JPC Constituted On 'One Nation One Election' Bills, Priyanka Gandhi, Anurag Thakur Among Members
Moment When Speed Boat Rammed Into 'Neelkamal' Ferry, Which Capsized Killing 13 In Mumbai — On Cam
Moment When Speed Boat Rammed Into 'Neelkamal' Ferry, Which Capsized Killing 13 In Mumbai — On Cam
'PM Modi Should Sack Amit Shah By Midnight If...': Congress' Big Attack On Centre Over Ambedkar Issue
'PM Modi Should Sack Amit Shah By Midnight If...': Congress' Big Attack On Centre Over Ambedkar Issue
Advertisement
ABP Premium

Videos

Priyanka Gandhi's bag creates a stir in politics, listen to what the Congress MP says in answer to the questions | ABP NewsParliament Session: Mallikarjun Kharge's allegation, 'Amit Shah insulted Baba Saheb Ambedkar' | ABP newsParliament Session: What did Shah say in Parliament after which Congress accused him of insulting AmbedkarParliament Session: 'Let me tell the 54-year-old youth who wants to change the Constitution...' Amit Shah

Photo Gallery

Embed widget