Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Loki Locker (BlackBit) Ransomware (.Loki, .BlackBit, .Rainman) Support Topic


  • Please log in to reply
38 replies to this topic

#31 icam22

icam22

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:45 PM

Posted 05 September 2023 - 03:06 AM

help pls, my computer has been attacked by loki ransomware

 

!!!All of your files are encrypted!!!

To decrypt them send e-mail to this address: lokiloki@mailfence.com

In case of no answer in 24h, send e-mail to this address: Lokisupp0rt@yandex.com

All your files will be lost on Wednesday, October 4, 2023 6:15:51 PM.

Your SYSTEM ID : E2964AD5

!!!Deleting "Cpriv.Loki" causes permanent data loss.



BC AdBot (Login to Remove)

 


#32 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 05 September 2023 - 06:13 AM

There is no known method that I am aware of to decrypt files encrypted by Loki Locker Ransomware without paying the ransom (not advisable) and obtaining the private encryption keys from the criminals who created the ransomware unless they are leaked or seized & released by authorities.
 
Your best option is to restore from backups, try file recovery software to recover (not decrypt) some of your original files or backup/save your encrypted data as is and wait for a possible solution at a later time. 

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#33 rivitna

rivitna

  •  Avatar image
  • Security Colleague
  • 220 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:45 AM

Posted 15 September 2023 - 07:01 PM

System ID is the serial number of your system volume.
You should not allow the destruction of your data after 30 days!!!
LokiLocker (but not BlackBit) may contain a Meterpreter payload, be carefull!
Affiliates usually give a decryptor, one decryptor per host. It doesn't cost a lot of money, but I am categorically against paying a ransom.
The RSA session key is either downloaded from the Internet (usually BlackBit) or generated on the host (usually LokiLocker), but decryption is not possible without it.
If Cpriv.* exists (and string "!!!Deleting "Cpriv.*" causes permanent data loss." in a ransom note) , the session key is generated on the host.
I have 7 sets of LokiLocker / BlackBit RSA public keys, BlackBit uses only one key set.
Protect your public RDP! Good luck!


Edited by rivitna, 15 September 2023 - 07:15 PM.


#34 RogerDingo

RogerDingo

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  

Posted 19 October 2023 - 03:21 PM

howdy

 

ive been hit with the blackbit malware on my server at home... so annoying.

 

ive tried malwarebytes, eset cleaner, combo cleaner and none of them work as expected...

malwarebytes and eset picked up a lot of malware files which seemed to relate to blackbit and it did quarantine them all.. but files are still encrypted. 

 

it sounds like theres no way to clean this up... so im going to need to reinstall my OS from scratch.

 

ahhh i reckon my NAS got infected as well.. would mean all my data is screwed


Edited by RogerDingo, 19 October 2023 - 03:23 PM.


#35 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 19 October 2023 - 03:29 PM

If you need individual assistance from our experts ONLY with removing the malware infection, (not decryption of your data), there are advanced tools which can be used to investigate but they are not permitted in this forum. Please follow the instructions in the Malware Removal and Log Section Preparation Guide. When you have done that, start a new topic and post your FRST logs in the Virus, Trojan, Spyware, and Malware Removal Logs Forum, NOT here, for assistance by the Malware Response Team.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#36 icam22

icam22

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:45 PM

Posted 27 December 2023 - 08:41 PM

still no decryptor for this malware?



#37 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 27 December 2023 - 08:50 PM

There is nothing new to report that I am aware of.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#38 rivitna

rivitna

  •  Avatar image
  • Security Colleague
  • 220 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:45 AM

Posted 28 December 2023 - 02:37 AM

Unfortunately, no solution yet



#39 lagm-cl

lagm-cl

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:45 AM

Posted 29 March 2024 - 06:47 PM

First of all, thank you for the advice on how to better address these challenges.
 
I have read each message regarding the Loki Locker ransomware and I have separated the system and data disks. I also reinstalled Windows Server, the applications, and the backed-up data.
 
I am waiting for some solution.
 
Have a great day

Edited by lagm-cl, 29 March 2024 - 06:58 PM.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users