CISA has released a decryption tool for victims that were breached by the VMware ransomware.
Over 3,800 people were hacked by the ransomware.
- According to CISA, the decryption tool is a script that does not delete the encrypted files but creates new config files that enable access to the VMs.
- The agency has stated that the script should be carefully analyzed before being deployed since it could negatively impact the system in which it is used.
- VMware has released a statement saying that hackers are using multiple security flaws that affect significantly outdated devices.
- Researchers believe that victims have paid at least $88,000 in ransom to the threat actor behind VMware, even though the actual number is likely higher.
- The company has advised its customers to upgrade to the latest available supported releases of vsphere components.