What might sound as unbelievable to most, CryptXXX ransomware is distributing decryption keys for free, without taking any money from the victims. In case you were one of the victims foxed by CryptXXX ransomware and have your data locked, you may get the unlocking key free from the payment sites of the ransomware.
This news came into reckoning yesterday, when victims visiting the Tor-based payment sites of CryptXXX ransomware, accidentally discovered that after logging in with their IDs, instead of receiving instructions on how to make the payment they were instead given the decryption keys for free.
As of now, CryptXXX ransomware is providing free keys only for certain variants of CryptXXX, namely those that add the .Crypz and .Cryp1 extensions to the encrypted files.
Why CryptXXX ransomware is leaking keys as free
Currently, there is no reliable explanation of why CryptXXX ransomware is providing keys as free. It would be unwise to think that CryptXXX developers are suddenly showing mercy on victims. A logical reason could be the existence of a bug within the CryptXXX ransomware server which is leaking keys to the users.
Bleeping Computer says,
“It could be that the developers are throwing a bone to their victims, but my guess is that it is a malfunction on their payment server that is causing this. The devs have been known in the past to provide buggy code and decryptable variants, so another error like this would not be hard to imagine”.
Victims looking to find the decryption key must note that keys provided by CryptXXX ransomware are specific for an individual victim and not a master. Hence the same key cannot be used by multiple users.
Lawrence lists the all known variants of the CryptXXX ransomware as given below.
Keys being offered for Free
- .Crypz Extension (UltraDecryptor)
- .Cryp1 Extension (UltraDecryptor)
Does not provide a Free Key
- .Crypt Extension (UltraDeCrypter)
- .Crypt Extension (Google Decryptor)
- Random Extension (UltraDecryptor)
- No extension (Microsoft Decryptor)
For more information, go here.
Stay safe, protect yourself against ransomware attacks.