The threat actor behind the lesser-known AstraLocker ransomware is shutting down the operation and plans to switch to cryptojacking.
The ransomware's developer submitted a ZIP archive with AstraLocker decryptors to the VirusTotal malware analysis platform. It is assumed that due to the sudden publicity brought by recent reports, AstraLocker has taken this decision.
A universal decryptor for AstraLocker ransomware is currently in the works, to be released in the future by Emsisoft, a software company known for helping ransomware victims with data decryption. The list of decryption tools released in the past includes Avaddon, Ragnarok, SynAck, TeslaCrypt, Crysis, AES-NI, Shade, FilesLocker, Ziggy, and FonixLocker.
The AstraLocker 2.0 ransomware is distributed directly from Microsoft Office files that victims are tricked into opening. The approach used with AstraLocker 2.0 underscores the risk posed to organizations following code leaks like that affecting Babuk, as a large population of low-skill, high-motivation actors leverage the leaked code for use in their own attacks.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.



