Trending

ee-track">
HomeBlog
Petya and Paradise Ransomware Source Codes Leaked

Petya and Paradise Ransomware Source Codes Leaked

The darkweb and cybercrime community is full of twists and interesting developments. A few days ago, a reputed operator in a cybercrime market with the alias ‘Krypt0n’ leaked the source code of the infamous ransomware Petya.

The author of the original Petya ransomware is a group known by the name of Janus Cybercrime solutions and has operated since 2016.

Back in 2017, the original author also leaked the master description key – after a year of their operations.

image 5
Post by the alias ‘Krypt0n’ – Source code of Petya

Here is the directory structure of their source code and its components:

image 7
Petya Ransomware Source Code
image 10

Several ransomware builders have been leaked recently, such as Paradise, leaked by the same actor ‘Krypt0n’.

image 8
Paradise Ransomware Source Code #1
image 9
Paradise Ransomware Source Code Leak

What to expect next? Other threat actors can create new variants or customized ransomware builders to help them build their own ransomware operations with these source codes.

report-ad-banner

Organizations should implement the following best practices to strengthen the security posture of their organization’s systems.   

  • Check for instances of standard executables executing with the hash of another process. 
  • Implement multi-factor authentication (MFA), especially for privileged accounts. 
  • Use separate administrative accounts on different administration workstations.   
  • Employ Local Administrator Password Solution (LAPS).   
  • Allow the least privilege to employees on data access.   
  • Use MFA to secure Remote Desktop Protocol (RDP) and ”jump boxes” for access.   
  • Secure your endpoints by deploying and maintaining endpoint defense tools.   
  • Always keep all software up-to-date.   
  • Keep antivirus signatures and engines up-to-date.   
  • Avoid adding users to the local administrators’ group unless required.   
  • Implement a strong password policy and enforce regular password changes.   
  • Configure a personal firewall on organization workstations to deny unwanted connection requests. 
  • Deactivate unnecessary services on organization workstations and servers. 

Disclaimer: This blog is based on our research and the information available at the time of writing. It is for informational purposes only and does not constitute legal, financial, or professional advice. While we strive for accuracy, we do not guarantee the completeness or reliability of the content. If any sensitive information has been inadvertently included, please contact us for correction. Cyble is not responsible for any errors, omissions, or decisions made based on this content. Readers should verify findings and seek expert advice where necessary. All trademarks, logos, and third-party content belong to their respective owners and do not imply endorsement or affiliation. All content is presented “as is” without any guarantee that it is free of confidential, proprietary, or otherwise sensitive information. If you believe any portion of this content contains inadvertently shared or sensitive data, please contact us immediately so that we may address and rectify the issue. No Liability for Errors or Omissions Due to the dynamic nature of cyber threat activity, this [blog/report/article] may include partial, outdated, or otherwise incorrect information due to unverified sources, evolving security threats, or human error. We expressly disclaim any liability for errors or omissions or any potential consequences arising from the use, misuse, or reliance on this information.

Get Threat Assessment Report

Identify External Threats Targeting Your Business​
Free

Sectoral Threat Reports

Upcoming Webinars

CISO's Guide to Threat Intelligence 2024

CISO’s Guide to Threat Intelligence 2024: Best Practices

Stay Ahead of Cyber Threats with Expert Insights and Strategies. Download Free E-Book Now

Subscribe Now

Share the Post:
Scroll to Top