Menu
A free decryption tool is now available for all Bart ransomware versions

A free decryption tool is now available for all Bart ransomware versions

Antivirus vendor Bitdefender obtained the Bart decryption keys from the Romanian police

Users who have had their files encrypted by any version of the Bart ransomware program are in luck: Antivirus vendor Bitdefender has just released a free decryption tool.

The Bart ransomware appeared back in June and stood out because it locked victims' files inside ZIP archives encrypted with AES (Advanced Encryption Standard). Unlike other ransomware programs that used RSA public-key cryptography and relied on a command-and-control server to generate key pairs, Bart was able to encrypt files even in the absence of an internet connection.

The original implementation of Bart did have some weaknesses and security researchers from antivirus firm AVG, which is now part of Avast, created a tool that could guess the password for the ransomware's archives using brute-force methods. The decryptor required the user to have at least one unaffected copy of a file that had been encrypted.

In later versions, the Bart developers changed their crypto implementation, rendering the AVG decryptor ineffective. According to Catalin Cosoi, chief security strategist at Bitdefender, the encryption used by the latest Bart variants is strong and has no obvious flaws.

Despite that, Bitdefender was able to create a decryption tool after the Romanian police provided them with the necessary keys, which were probably obtained during an investigation. The company credits collaboration with the Romanian Police and Europol for its success in creating the tool.

The tool was published on NoMoreRansom.org, a support website for ransomware victims that's maintained by a coalition of security vendors and law enforcement agencies. The website has prevention advice as well as a set of decryption tools that work for various strains of ransomware.

Some researchers believe Bart to be related to another widespread ransomware program, called Locky, that has affected many organizations in 2016. Files affected by this program have the .bart.zip, .bart and .perl extensions.

As always, having a backup plan in place is the best approach to deal with potential ransomware infections, rather than hoping for a free decryption tool that might or might not work for the particular variant that ends up affecting your files.

In the absence of backups, security experts advise against paying ransom because it encourages cybercriminals and doesn't always result in file recovery. The affected files should be saved though in case a solution to recover them is found at a later date.


Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Featured

Slideshows

Sizing up the NZ security spectrum - Where's the channel sweet spot?

Sizing up the NZ security spectrum - Where's the channel sweet spot?

From new extortion schemes, outside threats and rising cyber attacks, the art of securing the enterprise has seldom been so complex or challenging. With distance no longer a viable defence, Kiwi businesses are fighting to stay ahead of the security curve. In total, 28 per cent of local businesses faced a cyber attack last year, with the number in New Zealand set to rise in 2017. Yet amidst the sensationalism, media headlines and ongoing high profile breaches, confusion floods the channel, as partners seek strategic methods to combat rising sophistication from attackers. In sizing up the security spectrum, this Reseller News roundtable - in association with F5 Networks, Kaspersky Lab, Tech Data, Sophos and SonicWall - assessed where the channel sweet spot is within the New Zealand channel. Photos by Maria Stefina.

Sizing up the NZ security spectrum - Where's the channel sweet spot?
Kiwi channel comes together for another round of After Hours

Kiwi channel comes together for another round of After Hours

The channel came together for another round of After Hours, with a bumper crowd of distributors, vendors and partners descending on The Jefferson in Auckland. Photos by Maria Stefina.​

Kiwi channel comes together for another round of After Hours
Consegna comes to town with AWS cloud offerings launch in Auckland

Consegna comes to town with AWS cloud offerings launch in Auckland

Emerging start-up Consegna has officially launched its cloud offerings in the New Zealand market, through a kick-off event held at Seafarers Building in Auckland.​ Founded in June 2016, the Auckland-based business is backed by AWS and supported by a global team of cloud specialists, leveraging global managed services partnerships with Rackspace locally.

Consegna comes to town with AWS cloud offerings launch in Auckland
Show Comments