Victims of the MortalKombat ransomware variant were given a lifeline after Bitdefender released a new decryption key on Tuesday.
The security firm said it has been monitoring MortalKombat since it appeared in January of this year.
“Based on the Xorist ransomware, MortalKombat spreads via phishing emails and targets exposed RDP instances,” it explains. “Malware is planted via a BAT loader that also delivers the Laplas Clipper malware.”
In fact, it is the variant’s underlying Xorist codebase that allows security researchers to deliver decryption keys in record time. Xorist is a commodity ransomware family and decryption tools have been available for several years.
MortalKombat victims’ data is encrypted and “Remember_you_got_only_24_hours_to_make_the_payment_if_you_dont_pay_prize_will_triple_Mortal_Kombat_Ransomware.
The desktop wallpaper was also changed to a Mortal Kombat theme and a ransom note titled “How to decrypt files.txt” was also found.
According to Bitdefender, its decryptor can also be run in silent mode via command line. This is especially useful for organizations that want to automate deployment within large networks.
As reported by Information securitywe also observed the original MortalKombat threat actor dropping the Laplas Clipper clipboard stealer malware targeting cryptocurrency users.
“Laplas Clipper targets users by using regular expressions to monitor cryptocurrency wallet addresses in the clipboard of victim machines,” Cisco Talos said in its initial report on the campaign.
“When the malware finds a victim’s wallet address, it sends it to an attacker-controlled clipper bot, which generates a similar wallet address and overwrites it on the victim’s machine’s clipboard. Victims then attempt to use similar wallet addresses during transactions, resulting in fraudulent cryptocurrency transactions.”
The announcement of Bitdefender’s latest decryption key comes on the heels of similar tools designed to help victims of MegaCortex ransomware variants. That key was released in January of this year, while the previous LockerGaga ransomware family key was released in September 2022.
Editorial Credit Icon Image: Ralf Liebhold / Shutterstock.com