Cry128 ransomware no longer dangerous – victims can decrypt their files for free
Cry128 virus is a ransomware[1] program that is believed to be part of CryptON ransomware group[2]. It uses a modified AES-128 algorithm to encrypt all files on victim’s computer, excluding C:\Windows and C:\Program Files folders to keep the system running. The virus tends to mark each encrypted file with a long extension that typically consists of victim’s ID, and .onion website address, which points to a personal victim’s website with instructions on how to pay a ransom and restore encrypted files. _DECRYPT_MY_FILES.txt is the ransom note[3] that virus creates and saves on the desktop. If you found it on your computer, we suspect that your files were marked with one of the following file extensions. If so, you should immediately take actions and initiate Cry128 removal without a wait.
- .fgb45ft3pqamyji7.onion.to._
- .id-_[qg6m5wo7h3id55ym.onion.to].63vc4
- .id__gebdp3k7bolalnd4.onion._
- .id__2irbar3mjvbap6gt.onion.to._

The virus typically asks for 0.388 BTC[4] (which, according to the ransom note, equals to 722 USD, although due to always changing currency exchange rates this price can be either bigger or smaller. We have also seen versions that ask for 0.13793 BTC (~$200), although we suspect that the criminals lowered the ransom price only because security researchers from Emsisoft have created Cry128 decrypter that can restore all encrypted files for free. Before using it, of course, you should firstly remove Cry128 ransomware from the system, for example, using FortectIntego software.
CryptON spin off spreads using traditional ransomware distribution methods
The ransomware started attacking computer users since 22 April 2017. It mainly attacks victims via RDP (Remote Desktop Protocol)[5], attempting to brute force the login key to get access to target servers. To protect yourself from such attacks, you should only use very complex passwords and use a different account for Administrator’s access (most people use Administrator’s account, which makes the brute-force process easier since attackers already know the login name), and, of course, use two-factor authentication. Of course, the system must be guarded by an active an up-to-date security software at all times. Speaking of other traditional malware distribution techniques, we must mention malspam and malvertising as well as exploit kits. Such techniques are considered to be more sophisticated, therefore they are used only by ransomware professionals, and we can mention Cerber or Locky here.

Remove Cry128 ransomware and decrypt your files
Do not hesitate and remove Cry128 virus so that you could start the file decryption procedure. Researchers have already revealed a decrypter for this ransomware; however, we have to warn people and say that the decrypter is not yet capable of decrypting all versions of the malicious ransomware. It works for the most of them, so you should definitely try using it. Before you start, complete Cry128 removal using guidelines provided below. After decrypting your files, do not forget to create a data backup in case your computer becomes compromised by ransomware in the future.
Was this guide helpful?
Be the first to comment