AstraLocker ransomware closes its operation and releases decryptors on MalwareBazaar
AstraLocker ransomware’s developer has decided to shut down it’s operations and plans to issue AstraLocker decryptors in the system. The ransomware will release a ZIP archive along with the AstraLocker decoders to the VirusTotal malware analysis platform.
However, the reason behind the AstraLocker shutdown is still unknown but it’s likely because of the sudden publicity which brought its operation in focus with law enforcement’s
Consequently, this decryptor have been uploaded on MalwareBazaar. MalwareBazaar is a project where malware samples are shared with the infosec community, AV vendors and threat intelligence providers.
We have uploaded their decryptors to MalwareBazaar. https://t.co/jtPLfFDHVU pic.twitter.com/7O6nDRLza0
— Lawrence Abrams (@LawrenceAbrams) July 4, 2022
Now, before encrypting the files on the devices, the ransomware will check if the file is running in a virtual machine, kill processes and then will end backup and AV services which obstructs the encryption process.
Currently, the decoder for AstraLocker ransomware globally is under work. It will be issued in the future by the software company Emsisoft.