Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Kaspersky battles back against CryptXXX ransomware

Add as a preferred source on Google

Security experts at Kaspersky have developed a tool that can counteract the ransomware known as CryptXXX. The Russian company has now released the utility as a free download available to anyone who has been affected by the devious piece of malware.

First discovered earlier this month, CryptXXX presents certain advances over the strategies we’ve come to expect from ransomware. Like most attacks of this kind, it encrypts the files on your computer using the .crypt extension, at which point the targeted user is prompted to pay a sum of $500 in Bitcoin in order to regain access.

Recommended Videos

However, unlike other pieces of ransomware, CryptXXX also encrypts files that happen to be on any attached data storage devices. It also rifles through your hard drive for sensitive data, as well as hoovering up any Bitcoin funds that you might have left unprotected.

Previously, the attack would leave the targeted computer incapable of doing anything but displaying the ransom message. However, Kaspersky has updated its RannohDecrypter tool to be able to handle CryptXXX as well as Rannoh, the similar form of ransomware that it was originally designed to combat.

However, the utility does require something from the user — a single non-encrypted version of a file that was locked away by CryptXXX. So long as there’s a backup of such a file available, then the victim can download Kaspersky’s RannohDecrypter tool from here and follow the associated instructions to regain control of their system.

CryptXXX has met its match for now, but Kaspersky’s John Snow warns that hackers might soon find ways to work around RannohDecrypter, according to a report from ZDNet. According to Snow, the best protection against attacks like this is to perform regular security scans, and to avoid unscrupulous websites and strange links.

Brad Jones
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
macOS clipboard app Maccy has a fake out there stealing passwords
PamStealer malware is disguising itself as Maccy to target Mac users
Depicting of the Maccy clipboard app for macOS on a laptop with letters inb the background.

A fake version of Maccy, a popular clipboard manager for macOS, is being used to deliver a newly discovered Mac malware strain called PamStealer. Researchers at Jamf say the malware impersonates the real open-source app, but its actual purpose is to steal data and capture a victim’s login password.

PamStealer arrives as a disk image containing an AppleScript file that impersonates Maccy. Once the user opens that file, macOS launches it in Script Editor, where the on-screen instructions tell them to press Command-R. To someone expecting a normal app installer, that may look like an odd setup step. In reality, that action runs hidden malware code and starts the attack.

Read more
A new technology teaching drones to feel pain could stop your self-driving car from harming itself
Drones first, autonomous cars next. A pain-sensing system that detects failure before it happens has real stakes for self-driving vehicles.
Transportation, Vehicle, Car

When you sprain your ankle in the middle of a run, your body sends a pain signal to your brain, forcing you to stop. Essentially, the ability to sense pain stops you from pushing through the injury and causing further self-harm.

Researchers at Delft University of Technology and Wageningen University have applied this exact concept to drones, giving them a digital equivalent of a nervous system that recognizes a faulty part and triggers a pain-like warning signal. What's even more interesting is that the technology could find use in self-driving cars.

Read more
Claude Fable 5 is leaving subscriptions, but maybe not for good
High demand is pushing Claude Fable 5 out of subscriptions for now
Claude Fable 5 and Claude Mythos 5 Official Render

Anthropic’s most advanced publicly available Claude model is still leaving standard subscription access after July 7, but the company is now trying to calm fears that the move is permanent.

Fable 5 recently returned to Claude after drawing scrutiny from the U.S. government. Anthropic said it would be included on Pro, Max, Team, and select Enterprise plans for up to 50% of weekly usage limits through July 7. After that date, the model is set to move to usage-credit billing, meaning users will pay for access outside their regular plan limits.

Read more