A new version of TeslaCrypt has been released that is now using the ccc extension when encrypting files. This version utilizes the same payment site as previous variants and requires a 2 bitcoin, or approximately $500 USD, ransom in order to decrypt your files. Unfortunately, there is no way to decrypt this version for free at this time due to how the private decryption keys are generated.  The ransom notes for this version are named howto_recover_file_.txt and howto_recover_file_.html. These ransom notes are generated in each folder that a file has been encrypted and on your Windows desktop.

Unfortunately with .CCC version, there is no way to retrieve the private key for your encrypted files. As explained by our resident TeslaCrypt expert, BloodDolly:

TeslaCpryt ccc variant stores only public key of SHA256 of generated private key of bitcoinaddress. Private key can be shown only when it is calculated in memory as openssl BN, so it is in allocated memory so you have to dump the whole process memory space if you want to catch it and after SHA256, public key and ECDH shared secret with their hardcoded public key is calculated (this information is sent to their server) from this number, it is discarded. Files are encrypted by another random generated private key and this key is only available in allocated memory during the encryption process. File header and recovery_file contains only public keys and ECDH shared secrets with public key of SHA256 of bitcoin address.

So if you want to decrypt your files you need to know their private key or private key of your generated bitcoin address or SHA256 of this number or each single private key generated for your files (this can be 1 or more numbers).

As always, we will post about any new developments that may occur.

 

Related Articles:

Patelco shuts down banking systems following ransomware attack

Affirm says cardholders impacted by Evolve Bank data breach

Prudential Financial now says 2.5 million impacted by data breach

CDK Global says all dealers will be back online by Thursday

Meet Brain Cipher — The new ransomware behind Indonesia's data center attack