{"id":36022,"date":"2021-02-08T14:20:36","date_gmt":"2021-02-08T12:20:36","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=36022"},"modified":"2025-08-29T04:14:53","modified_gmt":"2025-08-29T01:14:53","slug":"ziggy-ransomware-halts-operations-hacker-publishes-decryption-keys","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/ziggy-ransomware-halts-operations-hacker-publishes-decryption-keys\/","title":{"rendered":"Ziggy ransomware halts operations; hacker publishes decryption keys"},"content":{"rendered":"<p>The creator of the Ziggy ransomware announced that it had ceased operation and released the keys to decrypt the infected files. According to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ziggy-ransomware-shuts-down-and-releases-victims-decryption-keys\/\" target=\"_blank\" rel=\"noopener noreferrer\">\u0441\u043e\u043e\u0431\u0449\u0430\u0435\u0442<\/a> BleepingComputer.<!--more--><\/p>\n<p>The hacker explained the decision amid concerns over the recent <a href=\"https:\/\/u1f987.com\/en\/news\/us-and-bulgarian-authorities-report-successful-operation-against-netwalker-ransomware\">arrest of the developers<\/a> of the Emotet and Netwalker ransomware.<\/p>\n<p>On February 7 he published an SQL file containing 922 decryption keys. For each victim, three keys are listed that are necessary for decryption.<\/p>\n<div id=\"attachment_124275\" style=\"width: 1610px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-124275\" class=\"size-full wp-image-124275\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/sql-file.jpg\" alt=\"\u0412\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c Ziggy \u043f\u0440\u0435\u043a\u0440\u0430\u0442\u0438\u043b \u0440\u0430\u0431\u043e\u0442\u0443. \u0425\u0430\u043a\u0435\u0440 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b \u043a\u043b\u044e\u0447\u0438 \u0434\u0435\u0448\u0438\u0444\u0440\u043e\u0432\u043a\u0438\" width=\"1600\" height=\"936\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/sql-file.jpg 1600w, https:\/\/u1f987.com\/wp-content\/uploads\/sql-file-300x176.jpg 300w, https:\/\/u1f987.com\/wp-content\/uploads\/sql-file-1024x599.jpg 1024w, https:\/\/u1f987.com\/wp-content\/uploads\/sql-file-768x449.jpg 768w, https:\/\/u1f987.com\/wp-content\/uploads\/sql-file-1536x899.jpg 1536w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/><\/p>\n<p id=\"caption-attachment-124275\" class=\"wp-caption-text\">Source: BleepingComputer.<\/p>\n<\/div>\n<p>The Ziggy author also posted a VirusTotal decryptor that works with the keys from the file, and shared the source code of the program for standalone decryption with Emsisoft.<\/p>\n<p>Its specialists are already working on developing an application.<\/p>\n<blockquote>\n<p>&#8220;Victims of the ransomware will be able to recover their data without paying the ransom and use the developer&#8217;s decryptor, which may contain a backdoor or bugs,&#8221; said Emsisoft expert Michael Gillespie.<\/p>\n<\/blockquote>\n<p>Earlier, the creators of the Fonix ransomware announced that it had shut down, and they also shared keys for restoring files.<\/p>\n<p>In January, Bitdefender antivirus developers released <a href=\"https:\/\/u1f987.com\/en\/news\/bitdefender-releases-free-decryptor-for-darkside-ransomware-encrypted-files\">a free decryptor for files<\/a>, encrypted by the Darkside virus.<\/p>\n<p>Follow ForkLog news on <a href=\"https:\/\/twitter.com\/ForkLog\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Twitter<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Ziggy ransomware creator announced that the operation had ceased and released the decryption keys for the infected files, according to BleepingComputer.<\/p>\n","protected":false},"author":1,"featured_media":36023,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154],"class_list":["post-36022","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes"],"aioseo_notices":[],"amp_enabled":true,"views":"19","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/36022","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=36022"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/36022\/revisions"}],"predecessor-version":[{"id":36024,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/36022\/revisions\/36024"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/36023"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=36022"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=36022"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=36022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}