Ransomware Developer Asks Security Researcher for Help in Fixing Broken Crypto

starbuck

Malware Removal Specialist - Administrator
In Memory
Joined
Jul 16, 2014
Messages
1,147
Location
Midlands, England
Fabian Wosar, Emsisoft security researcher, is facing a moral dilemma like very few security researchers have faced before.

Wosar, who is also a user of the Bleeping Computer forums where he's been active for the past few years helping ransomware victims, has received a private message from a user that has identified himself as one of the people who coded the Apocalypse ransomware.

During their exchange, the ransomware coder has asked Wosar to help their crew fix a bug in the ransomware's encryption process that causes files to be overwritten with junk data.

Crook tries to secure Wosar's help, for the victims' sake

In order to secure Wosar's help, the ransomware coder has appealed to the researcher's dedication to helping ransomware victims.
The crook says that if Wosar helps, they'll be able to provide a ransomware variant that doesn't destroy users' files.

The ransomware author was very candid with Wosar in his request.
He said that even if Wosar helps or not, money is more important to them, and they'll continue to spread their ransomware as they have been doing for the past six months.

The only ones that will have something to gain are the ransomware victims, who, if they decide to pay, will regain access to their files.
The request, in full, is below:

Once you have written that you feel sorry for the ransomware victims... You can help them.
As you know, now we use CryptoApi, and if encryption function fails - we just fil file with garbage.

As a result, after the decryption some victims crying to us... we try to keep an honest business, but money is more important to us, so some of the victims lose some of their files.

How you can help them? I know you are the best in cryptography, so we can send you the encryption and decryption code, and you should point us where is a bug, we will fix it and no more fake encryptions with garbage instead of the file content.

Indeed, a real moral dilemma.
For now, Wosar hasn't decided if he'll help or not.
There are arguments that for helping victims, but there's also the issue that he'll be aiding a criminal endeavor.

Source:
http://www.bleepingcomputer.com/new...-researcher-for-help-in-fixing-broken-crypto/
 
Back
Top