The main operator behind this Shade ransomware has suddenly stopped its operation at the end of 2019; not only this, even after shutting down the Shade ransomware the operator behind this ransomware has also released nearly 750k decryption keys.
The Shade, Troldesh, or Encoder.858 is generally a trojan-encryptor which is a ransomware, and according to the reports, it is speculated to be of Russian origin, that has been around since 2014.
While the most interesting thing in this incident is the “apology,” yes, the hackers or the operator behind this ransomware has also apologized to all the victims who got affected by this ransomware.
As we told earlier that this type of ransomware are occurring since 2014, and therefore, a security analyst from the Kaspersky Lab has reinforced the legality of the keys that are leaked and are now working to develop a free decryption tool.
Well, the operators of the Shade Ransomware have clearly stated that they have a specific reason for releasing this decryption tool, but they did not disclose the reason for doing so.
But, the security community is really shocked, as the operator of the Shade ransomware is one of the oldest and best ransomware forces. As we said before in this article that the first ransomware was spotted in 2014, and since then it has been operating continuously, till it got closed last year in the end of 2019.
The decryption keys that are released will surely help each user who had data encrypted by the Shade ransomware. And these key has an account of all version of the ransomware and all the users who got infected.
(Note: It may happen that the ID was also appended just after the file’s name in the latter versions of this ransomware.)
But be alert, as using all these keys are not very reliable, and most of the users encounter difficulty while operating it. But the decryption keys that have been released recently have some rules which were not straight, as you could see from the above steps, that’s why victims may face difficulty getting it to work correctly.
Moreover, Sergey Golovanov from Kaspersky has stated that said that the key is working and soon they will update their RakhniDecryptor, in which they will put all these keys so that victims could easily recover their files for free of cost.
You can also read the complete ransomware mitigation checklist
So, what do you think about this? Simply share all your views and thoughts in the comment section below.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Also Read:
Most Ransomware Attacks Take Place in the Night or During Weekends
Hackers Scanning Unpatched Citrix Server to Exploit and Deploy Ransomware
CTS Hacked – IT Service Giant Cognizant Hit With Ransomware Cyber Attack
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…