News

Ransomware Victim Hacks Attacker and Releases Decryption Keys

Giulio Saggin
Giulio Saggin
Tuesday 28 November 2023

A ransomware attacker got a taste of their own medicine when one of their victims hacked their server and released the decryption keys for other victims to use.

The attacker had used the Muhstik ransomware to encrypt the files of Tobias Fromel, a German software developer. Fromel paid the gang's 670 Euro (US$730) ransom but was still annoyed at what had happened, so he got his revenge.

"I hacked back this criminal and get the whole database with keys," he wrote in a text file - containing over 2,800 decryption keys - he published online. "I know it was not legal from me too but he used already hacked servers with several webshells on it... and I'm not the bad guy here."

Muhstik is a ransomware that appeared at the end of September this year and targets network-attacked storage (NAS) devices made by QNAP. According to a security advisory from QNAP, devices using weak SQL server passwords and running phpMyAdmin may be more vulnerable vulnerable to attack. The ransomware was dubbed Muhstik because of the .muhstik extension on encrypted files.

While Fromel's actions are illegal, it's doubtful charges will be brought against him (especially from the Muhstik attacker) for what many consider to be his 'Robin Hood' actions.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203