'Sad' About What They Did, Ransomware Administrators Refund Victims

Ransomware attacks can be a huge pain to deal with.

Not only that the attacks can hold important data to render them inaccessible, the attacks also demand ransom that isn't cheap. Making things worse, cybersecurity experts advise anyone who fell for ransomware attacks to never pay.

Victims are advised not to pay to discourage the bad actors from continuing what they do. But not paying means that people won't ever have the chance to receive the decryption keys.

That until this time, and for at least one type of ransomware.

Called the 'Ziggy' ransomware, the administrators of the ransomware have announced the end of their operation.

And with that, they are giving the decryption keys for whoever fell for their attacks, and also giving them their money back.

The administrators of the Ziggy ransomware saying that they want to return their victim's money
The administrators of the Ziggy ransomware saying that they want to return their victim's money. (Credit: BleepingComputer)

Ziggy ransomware was shut down in early February of 2021.

In a short announcement, the administrator of the ransomware said that they were “sad” about what they did and that they “decided to publish all decryption keys.”

The next day, on February 7, the administrators started offering an SQL file with 922 decryption keys that victims could use in order to unlock their files. Each infected system requires three keys.

And because crooks aren't to be trusted, the administrators are going to great length to show their goodwill, by also making the decryption tools easy to access, and published the decryptor to the public.

SQL file containing many Ziggy decryption keys
SQL file containing many Ziggy decryption keys. (Credit: BleepingComputer)

The administrators have even published offline keys, which are essentially decryptor keys that don't require internet connection, meaning that it won't connect to the hackers' command and controls servers whatsoever.

Then in March 19, the Ziggy ransomware administrator went further by saying that they also wanted to return the money to the victims that paid the ransom.

And about a week without any updates, the administrators finally showed up, saying that they are starting to revert those payments.

The administrators said that victims should contact them at a given email address ([email protected]) with the proof of their payment in Bitcoin and the computer ID.

If the victims are what they say they are, the administrators would then return their money to their Bitcoin wallets in about two weeks time.

[block:block=87]
An easy-to-use Ziggy ransomware decryptor
An easy-to-use Ziggy ransomware decryptor. (Credit: BleepingComputer)

“Hi. I am the Ziggy ransomware administrator. We decided to publish all decryption keys. We are very sad about what we did. As soon as possible, all the keys will be published in this channel,” the administrators said in a brief post on the Telegram messaging app.

“If you are infected with Ziggy ransomware and you payed money, We are ready to give back your money. Send you payment receipt and your computer unique ID to email. We will transfer money to your Bitcoin wallet address. We will give back your money until 2 weeks later.”

It seems that the administrators felt guilty about what they did, after realizing how much damage their victims have sustained because of Ziggy.

What's more, they know that the police and law enforcements are after them.

While the administrators have shown their good intentions, cybersecurity experts recommend victims to only use decryption tools made by security firms.

“The release of the keys, whether voluntarily or involuntarily, is the best possible outcome. It means past victims can recover their data without needing to pay the ransom or use the dev’s decryptor, which could contain a backdoor and/or bugs. And, of course, it also means there’s one less ransomware group to worry about,” one expert suggests.

This is why the administrators worked with ransomware expert Michael Gillespie, who created a decryptor for the Ziggy Ransomware using the released keys.

It's estimated that the Ziggy ransomware has at least between 300 and 350 victims.

Source code for the different Ziggy ransomware decryptor
Source code for the different Ziggy ransomware decryptor. (Credit: BleepingComputer)

In an interview with BleepingComputer on the Telegram messaging app, the administrators said that they live in a "third-world country", and their motivation for creating the Ziggy ransomware was purely about earning money.

And because everything is over, in order to come up with the money to pay their victims, they said that were selling their home to help finance the refunds.

While this case is unique, knowing that malware authors can show sympathy, a change of heart and fear, it should be noted that the administrators of the ransomware do profit from their campaign.

Bitcoin price has been on ascending for the past months.

On the day Ziggy ransomware decryption keys became public, Bitcoin price was around $40,000. Five days before the administrators announced that they would return the money, Bitcoin was well above $60,000. Given the price difference, the administrators do make a profit.

It should be noted that Ziggy's administrators aren't the first to have this goodwill intentions. Previously, the operators of Fonix reportedly have similar intentions in publishing their own decryptor keys, and have also apologized for what they did.

The news came after the law-enforcement takedowns of the Emotet and the NetWalker ransomware.