Victims hacked hackers' servers when they were caught paying ransom, rescuing thousands of other victims
Tobias Frömel, a German programmer and a victim of ransom to recover data stolen by hackers. This guy hacked the hackers' own device and helped unlock thousands of other victims of data theft.
Specifically, at the end of September, network-attached storage devices (NASs) manufactured by Taiwan hardware supplier QNAP were attacked with ransomware software called Muhstik. Hackers have encrypted data files and required each victim to pay 0.09 bitcoins, about $ 700 ransom.
After paying the ransom, Frömel analyzed the ransomware to understand how it works. After that, this guy decided to hack the server of the hacker.
Based on the data and information contained in the server, Frömel accessed the PHP script, created a new password and decoded for 2,858 victims who were hacked just like they were stored in the database.
Frömel also published a decoder on the BleepingComputer forum and a Twitter post that all Muhstik victims could use to unlock their files.

In his announcement, Frömel made it clear that he was not a bad guy and that his actions were not revenge. He knew it was illegal.
Some victims have used Frömel's decoder to decrypt their files themselves and have succeeded. Some even gave Frömel some bitcoins to thank.
A security researcher informed the authorities when he saw Frömel's share. He provided information on the behind hackers' party to the authorities in the hope that they would catch them soon. He added that Frömel's actions helped thousands of victims, making it difficult to be prosecuted even though it was an illegal act. The security researcher also advised Frömel to help the authorities track down the attackers.

To decode files encrypted by Muhstik, security firm Emsisoft has also released a decoder running on Windows operating systems. Compared to Frömel's way, this decoder has a simpler way of working. You can access the link below to use this decoder if you are a victim of Muhstik.
https://www.emsisoft.com/ransomware-decryption-tools/muhstik
- Just 5 minutes, hackers make 'ATM automatically release money', no password needed, no transaction record on the system
- New hacker tricks, increasingly more sophisticated, to avoid being exposed
You should read it
- Shade ransomware, the nightmare of 5 years ago is showing signs of returning
- Mexico's largest oil and gas corporation has been attacked by ransomware, presenting a cyber security disaster
- Warning: Dangerous new malicious code spills over to Vietnam
- 7 kinds of ransomware you didn't expect
- Shade Ransomware stopped working, apologized to the victims, and released 750,000 decryption keys
- STOP - Ransomware is the most active in the Internet but rarely talked about
- Detecting a new ransomware strain, not asking for data ransom, but only needing the victim to join the Hacker's Discord server
- Why is Ransomware the perfect hack?
May be interested
- MongoDB malicious code attacks more than 26,000 victims in a weekmalware that attacks the mongodb database has rekindled last week and after the weekend with the arrival of three new groups hijack more than 26,000 servers, of which one group attacked 22,000 machines.
- Apple device users are attacked by hackers remotely locking computersit is likely that hackers have taken advantage of the find my iphone feature to hack and lock devices such as iphone, ipad, mac ... then ransom the victim's ransom or delete the data.
- How do hackers attack your Facebok account and how to prevent this process?hackers can attack your facebook account in many different ways, such as attacking email addresses, phishing .... to better understand how hackers attack your facebook account and solutions to prevent this process, please refer to the following article of network administrator.
- Filipino hackers attack the Vietnamese web, retaliating that many users' Facebook accounts are 'hacked' by Vietnamese peoplethere is a cyber attack campaign targeting websites of vietnamese individuals and organizations launched by filipino hackers to retaliate against many 'hacked' filipino accounts by vietnamese people.
- In turn, Microsoft admitted being hacked because of the SolarWinds vulnerabilitymicrosoft has admitted that they were attacked by hackers through a vulnerability of solarwinds' software update system. however, the software giant denied that hackers used their software to infect users as well as customers.
- Can a VPN Protect You From Ransomware?ransomware is a worrisome online threat. if it's installed on your computer, you not only risk paying a ransom to get your files back, but you also potentially won't get them back even after paying.
- The leading site to learn hacking skillswhen it comes to hackers, perhaps the first model we imagine is college students or experts in computer science.
- Hacker attacks a US city demanding $ 100,000 ransom with Bitcoinhackers encrypted important city files and ransomed about $ 100,000 with bitcoin.
- TeamViewer is attacked by Chinese hackers, any computer logged in can be controlledteamviewer - a remote control tool used by a lot of people, has been hacked by chinese hackers.
- Upbit virtual currency exchange hacked, $ 48.7 million 'flying after the clouds'upbit, one of south korea's largest cryptocurrency exchanges, has become the latest name to join the list of victims of cryptocurrency thieves in 2019.