How security experts unravel ransomware

Hackers use ransomware to go after every industry, charging as much money as they can to return access to a victim's files. It’s a lucrative business to be in. In the first six months of 2023, ransomware gangs bilked $449 million from their targets, even though most governments advise against paying ransoms. Increasingly, security professionals are coming together with law enforcement to provide free decryption tools — freeing locked files and eliminating the temptation for victims to pony up.

There are a couple main ways that ransomware decryptors go about coming up with tools: reverse engineering for mistakes, working with law enforcement and gathering publicly available encryption keys. The length of the process varies depending on how complex the code is, but it usually requires information on the encrypted files, unencrypted versions of the files and server information from the hacking group. “Just having the output encrypted file is usually useless. You need the sample itself, the executable file,” said Jakub Kroustek, malware research director at antivirus business Avast. It’s not easy, but does pay dividends to the impacted victims when it works.

First, we have to understand how encryption works. For a very basic example, let's say a piece of data might have started as a cognizable sentence, but appears like "J qsfgfs dbut up epht" once it's been encrypted. If we know that one of the unencrypted words in "J qsfgfs dbut up epht" is supposed to be "cats," we can start to determine what pattern was applied to the original text to get the encrypted result. In this case, it's just the standard English alphabet with each letter moved forward one place: A becomes B, B becomes C, and "I prefer cats to dogs" becomes the string of nonsense above. It’s much more complex for the sorts of encryption used by ransomware gangs, but the principle remains the same. The pattern of encryption is also known as the 'key', and by deducing the key, researchers can create a tool that can decrypt the files.

Some forms of encryption, like the Advanced Encryption Standard of 128, 192 or 256 bit keys, are virtually unbreakable. At its most advanced level, bits of unencrypted "plaintext" data, divided into chunks called "blocks," are put through 14 rounds of transformation, and then output in their encrypted — or "ciphertext" — form. “We don’t have the quantum computing technology yet that can break encryption technology,” said Jon Clay, vice president of threat intelligence at security software company Trend Micro. But luckily for victims, hackers don’t always use strong methods like AES to encrypt files.

While some cryptographic schemes are virtually uncrackable it’s a difficult science to perfect, and inexperienced hackers will likely make mistakes. If the hackers don’t apply a standard scheme, like AES, and instead opt to build their own, the researchers can then dig around for errors. Why would they do this? Mostly ego. “They want to do something themselves because they like it or they think it's better for speed purposes,” Jornt van der Wiel, a cybersecurity researcher at Kaspersky, said.

For example, here’s how Kaspersky decrypted the Yanluowang ransomware strain. It was a targeted strain aimed at specific companies, with an unknown list of victims. Yanluowang used the Sosemanuk stream cipher to encrypt data: a free-for-use process that encrypts the plaintext file one digit at a time. Then, it encrypted the key using an RSA algorithm, another type of encryption standard. But there was a flaw in the pattern. The researchers were able to compare the plaintext to the encrypted version, as explained above, and reverse engineer a decryption tool now made available for free. In fact, there are tons that have already been cracked by the No More Ransom project.

Ransomware decryptors will use their knowledge of software engineering and cryptography to get the ransomware key and, from there, create a decryption tool, according to Kroustek. More advanced cryptographic processes may require either brute forcing, or making educated guesses based on the information available. Sometimes hackers use a pseudo-random number generator to create the key. A true RNG will be random, duh, but that means it won’t be easily predicted. A pseudo-RNG, as explained by van der Wiel, may rely on an existing pattern in order to appear random when it's actually not — the pattern might be based on the time it was created, for example. If researchers know a portion of that, they can try different time values until they deduce the key.

But getting that key often relies on working with law enforcement to get more information about how the hacking groups work. If researchers are able to get the hacker’s IP address, they can request the local police to seize servers and get a memory dump of their contents. Or, if hackers have used a proxy server to obscure their location, police might use traffic analyzers like NetFlow to determine where the traffic goes and get the information from there, according to van der Wiel. The Budapest Convention on Cybercrime makes this possible across international borders because it lets police request an image of a server in another country urgently while they wait for the official request to go through.

The server provides information on the hacker’s activities, like who they might be targeting or their process for extorting a ransom. This can tell ransomware decryptors the process the hackers went through in order to encrypt the data, details about the encryption key or access to files that can help them reverse engineer the process. The researchers comb through the server logs for details in the same way you may help your friend dig up details on their Tinder date to make sure they’re legit, looking for clues or details about malicious patterns that can help suss out true intentions. Researchers may, for example, discover part of the plaintext file to compare to the encrypted file to begin the process of reverse engineering the key, or maybe they’ll find parts of the pseudo-RNG that can begin to explain the encryption pattern.

Working with law enforcement helped Cisco Talos create a decryption tool for the Babuk Tortilla ransomware. This version of ransomware targeted healthcare, manufacturing and national infrastructure, encrypting victims' devices and deleting valuable backups. Avast had already created a generic Babuk decryptor, but the Tortilla strain proved difficult to crack. The Dutch Police and Cisco Talos worked together to apprehend the person behind the strain, and gained access to the Tortilla decryptor in the process.

But often the easiest way to come up with these decryption tools stems from the ransomware gangs themselves. Maybe they’re retiring, or just feeling generous, but attackers will sometimes publicly release their encryption key. Security experts can then use the key to make a decryption tool and release that for victims to use going forward.

Generally, experts can’t share a lot about the process without giving ransomware gangs a leg up. If they divulge common mistakes, hackers can use that to easily improve their next ransomware attempts. If researchers tell us what encrypted files they’re working on now, gangs will know they’re on to them. But the best way to avoid paying is to be proactive. “If you’ve done a good job of backing up your data, you have a much higher opportunity to not have to pay,” said Clay.

This article originally appeared on Engadget at https://www.engadget.com/how-security-experts-unravel-ransomware-184531451.html?src=rss

Roblox adds real-time AI chat translation using its own language model

Currently serving over 70 million daily active users, Roblox is still going strong since its September 2006 launch — almost 18 years ago. The development team is now taking one step further to boost the platform's massive community, by way of providing real-time AI chat translation to connect gamers around the world. According to CTO Daniel Sturman, his team needed to build their own "unified, transformer-based translation LLM (large language model)" in order to seamlessly handle all 16 languages supported on Roblox, as well as to recognize Roblox-specific slangs and abbreviations (this writer just learned that "obby" refers to an obstacle course in the game).

As a result, the chat window always displays the conversation in the user's own tongue — with a small latency of around 100 milliseconds, so it's pretty much real time. You can also click on the translation icon on the left of each line to see it in its original language. Sturman claims that thanks to the language model's efficient architecture and iterative training, it "outperforms commercial translation APIs on Roblox content." The development team will later roll out a feedback tool to help improve translation quality, in addition to its ongoing updates with whatever new catchphrases it picks up on the platform.

Roblox built its own large language model to support real-time chat translation for all 16 languages on its platform. It recognizes Roblox-specific slang and abbreviations.
Roblox

Roblox's translation efforts don't stop there. Sturman adds that his team is already looking into automatically translating "text on images, textures, 3D models" and more. As Roblox supports voice chat, the exec also teases the possibility of automatic voice chat translations, so gamers from around the world can seamlessly talk to one another in their own tongue on the platform. Given that Samsung already offers a similar feature via Galaxy AI, it probably won't be long before we hear another update from Roblox on this end.

This article originally appeared on Engadget at https://www.engadget.com/roblox-adds-real-time-ai-chat-translation-using-its-own-language-model-061929902.html?src=rss

Google is reportedly rebranding Bard to Gemini and plans to launch a dedicated app

According to a document leaked on X, Google is planning to introduce some major changes to its Bard AI tool as soon as this coming week. The plans, which have not been publicly confirmed, reportedly include changing the Bard name to Gemini. It would make sense for Google to do so, if only for simplicity’s sake — the company introduced its new multimodal AI model, Gemini, at the end of 2023 and has begun integrating it into some of its products, including Bard.

The changelog shared by Android app developer Dylan Roussel is dated February 7, and also notes that the paid Gemini Advanced tier will become available at this time. It mentions a Gemini app for Android is “coming soon,” as well.

Per the document, Gemini Advanced will give users access to the Ultra 1.0 model of Gemini, which is “far more capable at highly complex tasks like coding, logical reasoning, following nuanced instructions, and creative collaboration.” It’ll be available in over 150 countries and optimized for the English language at the start. The changelog also says Gemini will expand to Canada with this release.

This article originally appeared on Engadget at https://www.engadget.com/google-is-reportedly-rebranding-bard-to-gemini-and-plans-to-launch-a-dedicated-app-204442265.html?src=rss

Niantic is bringing an AR skateboarding game to Apple Vision Pro

Pokémon Go creator Niantic is bringing an AR skateboarding game to the Apple Vision Pro mixed-reality headset. The company teamed up with Reality Crisis, another player in the AR gaming space, to create Rodney Mullen’s SKATRIX. For the uninitiated, Mullen is a professional skateboarder who is credited with creating a number of iconic tricks, including the ollie and the kickflip.

This is the first augmented-reality skateboard game ever, unless you count using an actual skateboard to speed around town catching pocket monsters in Pokémon Go. Niantic says the gameplay will involve players navigating the real world to “explore and collect skatepark elements.” The game will use the same AR precision elements as the company’s other titles to “turn the world into an endless skatepark.” A gameplay demo shows an avatar skating in real-world locations like parking lots and inside of washing machines. However, there’s one really expensive elephant in the room.

The Apple Vision Pro costs $3,500 and isn’t exactly suited to removing from the living room, let alone the home. You’ll also look pretty stupid wearing Apple’s bulky ski goggles while out and about, not to mention it’d be mighty easy to snag it from your head and race away, perhaps on a real-life skateboard. 

To that end, Niantic and Reality Labs are also bringing the game to standard mobile devices, including iOS and Android smartphones. Much of the gameplay is still under wraps, but Niantic promises that players will be able to share custom-made skateparks with other users on both mobile devices and mixed-reality headsets.

Rodney Mullen’s SKATRIX will be released sometime this year. As for the Apple Vision Pro, the device looks to be getting all kinds of apps. The headset will have access to Microsoft’s entire 365 productivity suite at launch, along with a Zoom app. All told, Apple says there will be 600 apps available for tomorrow’s release.

This article originally appeared on Engadget at https://www.engadget.com/niantic-is-bringing-an-ar-skateboarding-game-to-apple-vision-pro-183740925.html?src=rss

Block is reportedly laying off around 1,000 workers

Block is the latest notable tech company to lay off hundreds of workers, according to reports. CEO Jack Dorsey is said to have informed employees that the company is firing a "large number" of them, with Cash App, Square and the foundational (i.e. operations) teams bearing the brunt of the impact. According to a Business Insider source, Block is letting go nearly 1,000 people.

Dorsey reportedly wrote in his memo that the company is becoming leaner. It laid off around 40 people from the Tidal team in December. Last year, Block said it planned to limit its headcount to around 12,000 workers, a reduction from the around 13,000 it had in late 2023. Engadget has contacted Block for confirmation of the layoffs.

While it was initially expected that the layoffs would take place over a period of months, executives reportedly opted against that in favor carrying them out at the same time. "Why is so much happening in one single day? All of these teams were confident in the direction they're taking, and were ready to take action within the same 2-3 weeks," Dorsey is said to have written in his memo. "We decided it would be better to do [it] at once rather than arbitrarily space them out, which didn't seem fair to the individuals or to the company. When we know we need to take an action, we want to take it immediately, rather than let things linger on forever."

The tech industry has shed tens of thousands of workers over the last year or so, including thousands this month alone across companies including Unity, Twitch, Amazon, Meta, Microsoft, eBay and Google. It also emerged on Tuesday that PayPal is firing around 2,500 people

This article originally appeared on Engadget at https://www.engadget.com/block-is-reportedly-laying-off-around-1000-workers-205319045.html?src=rss

A new Deus Ex game was reportedly canceled amid Embracer’s crisis

Embracer Group, the Swedish holding company undergoing restructuring, has reportedly canceled a Deus Ex game. Bloomberg says developers had been working on the unannounced title for two years. Neither Embracer nor developer Eidos addressed the reported cancellation specifically, but they confirmed they were laying off 97 employees at Deus Ex developer Eidos Montreal.

Eidos will reportedly focus instead on “an original franchise.” Bloomberg’s sources say the Deus Ex game was scheduled to start production later this year. The franchise’s most recent mainline installment was 2016’s Deus Ex: Mankind Divided.

After aggressively growing through acquisitions during the pandemic, Embracer Group entered a turbulent period last year. The company announced a restructuring plan in June 2023 after an unnamed partner pulled out of a planned deal that would have brought in $2 billion over six years. Axios later reported the mysterious investor was Savvy Games Group, which the Saudi government funds.

In August, Embracer announced the closure of Volition, the studio behind the Saints Row series. The parent company laid off about 900 employees in September and another 50 workers at Chorus developer Fishlabs. Earlier this month, Embracer shuttered Lost Boys Interactive, makers of Tiny Tina’s Wonderland — pinning the blame on “headwinds facing the industry right now.”

Embracer says the restructuring phase will run until the end of March. The company claims it will provide regular updates on the process, including when it publishes its next quarterly report on February 15.

Alongside the alleged Deus Ex cancellation, Eidos confirmed it let go of 97 employees from development teams, administration and support services. “The global economic context, the challenges of our industry and the comprehensive restructuring announced by Embracer have finally impacted our studio,” Eidos wrote in a statement.

This article originally appeared on Engadget at https://www.engadget.com/a-new-deus-ex-game-was-reportedly-canceled-amid-embracers-crisis-194919207.html?src=rss

A new Deus Ex game was reportedly canceled amid Embracer’s crisis

Embracer Group, the Swedish holding company undergoing restructuring, has reportedly canceled a Deus Ex game. Bloomberg says developers had been working on the unannounced title for two years. Neither Embracer nor developer Eidos addressed the reported cancellation specifically, but they confirmed they were laying off 97 employees at Deus Ex developer Eidos Montreal.

Eidos will reportedly focus instead on “an original franchise.” Bloomberg’s sources say the Deus Ex game was scheduled to start production later this year. The franchise’s most recent mainline installment was 2016’s Deus Ex: Mankind Divided.

After aggressively growing through acquisitions during the pandemic, Embracer Group entered a turbulent period last year. The company announced a restructuring plan in June 2023 after an unnamed partner pulled out of a planned deal that would have brought in $2 billion over six years. Axios later reported the mysterious investor was Savvy Games Group, which the Saudi government funds.

In August, Embracer announced the closure of Volition, the studio behind the Saints Row series. The parent company laid off about 900 employees in September and another 50 workers at Chorus developer Fishlabs. Earlier this month, Embracer shuttered Lost Boys Interactive, makers of Tiny Tina’s Wonderland — pinning the blame on “headwinds facing the industry right now.”

Embracer says the restructuring phase will run until the end of March. The company claims it will provide regular updates on the process, including when it publishes its next quarterly report on February 15.

Alongside the alleged Deus Ex cancellation, Eidos confirmed it let go of 97 employees from development teams, administration and support services. “The global economic context, the challenges of our industry and the comprehensive restructuring announced by Embracer have finally impacted our studio,” Eidos wrote in a statement.

This article originally appeared on Engadget at https://www.engadget.com/a-new-deus-ex-game-was-reportedly-canceled-amid-embracers-crisis-194919207.html?src=rss

Former Call of Duty chief Johanna Faries is Blizzard’s new president

Microsoft didn't have to look too far to find the new president of Blizzard. Former Call of Duty general manager Johanna Faries is replacing Mike Ybarra, who stood down from the role amid last week's sweeping layoffs in Microsoft's gaming division. Blizzard was said to be particularly hard hit as Microsoft fired around 1,900 people.

Faries, a former National Football League executive, joined Activision as the head of Call of Duty esports in 2018. She started overseeing all things Call of Duty in 2021 and officially starts her new role on February 5. 

Blizzard has largely operated independently since it merged with Activision in 2008. As such, Blizzard workers may be forgiven for being concerned at someone from the Activision side taking control. Former Activision Blizzard CEO Bobby Kotick often meddled in Blizzard's affairs, reportedly resulting in Overwatch 2 delays, among other things.

In an attempt to soothe any worries, Faries wrote in an email to staff that "Activision, Blizzard, and King are decidedly different companies with distinct games, cultures and communities. It is important to note that Call of Duty’s way of waking up in the morning to deliver for players can often differ from the stunning games in Blizzard’s realm: each with different gameplay experiences, communities that surround them, and requisite models of success. I’ve discussed this with the Blizzard leadership team and I’m walking into this role with sensitivity to those dynamics, and deep respect for Blizzard, as we begin to explore taking our universes to even higher heights."

Faries added that she is "committed to doing everything I can to help Blizzard thrive, with care and consideration for you and for our games, each unique and special in their own right.” Meanwhile, on X, Faries wrote that Blizzard's Diablo 4 was part of her current rotation of games, alongside Call of Duty and Baldur's Gate 3.

This article originally appeared on Engadget at https://www.engadget.com/former-call-of-duty-chief-johanna-faries-is-blizzards-new-president-193852238.html?src=rss

Former Call of Duty chief Johanna Faries is Blizzard’s new president

Microsoft didn't have to look too far to find the new president of Blizzard. Former Call of Duty general manager Johanna Faries is replacing Mike Ybarra, who stood down from the role amid last week's sweeping layoffs in Microsoft's gaming division. Blizzard was said to be particularly hard hit as Microsoft fired around 1,900 people.

Faries, a former National Football League executive, joined Activision as the head of Call of Duty esports in 2018. She started overseeing all things Call of Duty in 2021 and officially starts her new role on February 5. 

Blizzard has largely operated independently since it merged with Activision in 2008. As such, Blizzard workers may be forgiven for being concerned at someone from the Activision side taking control. Former Activision Blizzard CEO Bobby Kotick often meddled in Blizzard's affairs, reportedly resulting in Overwatch 2 delays, among other things.

In an attempt to soothe any worries, Faries wrote in an email to staff that "Activision, Blizzard, and King are decidedly different companies with distinct games, cultures and communities. It is important to note that Call of Duty’s way of waking up in the morning to deliver for players can often differ from the stunning games in Blizzard’s realm: each with different gameplay experiences, communities that surround them, and requisite models of success. I’ve discussed this with the Blizzard leadership team and I’m walking into this role with sensitivity to those dynamics, and deep respect for Blizzard, as we begin to explore taking our universes to even higher heights."

Faries added that she is "committed to doing everything I can to help Blizzard thrive, with care and consideration for you and for our games, each unique and special in their own right.” Meanwhile, on X, Faries wrote that Blizzard's Diablo 4 was part of her current rotation of games, alongside Call of Duty and Baldur's Gate 3.

This article originally appeared on Engadget at https://www.engadget.com/former-call-of-duty-chief-johanna-faries-is-blizzards-new-president-193852238.html?src=rss

Suicide Squad: Kill the Justice League pulled offline after a bizarre game-beating bug

Rocksteady’s new third-person action shooter Suicide Squad: Kill the Justice League has been pulled offline just one hour after launch when players encountered a bizarre bug that immediately beats the game. We’ve all heard of game-breaking bugs, but this may be the first game-beating bug. Obviously, players want more than three minutes of playtime out of their $70 purchase.

The issue immediately locks players out of all story missions, including tutorials, in a race to reach the end credits. This also makes it impossible to receive trophies and achievements, though most purchasers will probably get hung up on the whole “the game is basically unplayable” aspect. Still, if you’re looking for the easy mode to beat all easy modes, this is it. We could have used this bug for Sekiro: Shadows Die Twice or Cuphead.

There’s one major caveat here that’s saving this from becoming a huge story comparable with the disastrous launch of Cyberpunk 2099, and many other recent AAA launches. The game doesn’t officially release in most of the world until February 2. Some territories get it tomorrow, January 30, and that’s where the bug comes in. Due to the magic of global time zones, it’s already January 30 in New Zealand, which is where players encountered the issue. However, it’s not too hard to change your Xbox system clock to New Zealand time to snag the game early. Don’t do that. Give Rocksteady some time to fix the problem.

To that end, the developer says they are working on a fix, which involves performing maintenance on the servers. Rocksteady urges patience, writing that it could take “several hours” before being handled. Throughout this time, the game will remain offline. In any event, the ship should right itself before February 2.

Looking for a silver lining? Being as how the bug skips the vast majority of the game, the risk of story spoilers is really low for the next few days. So go ahead. Hit up your favorite social media sites and message boards.

This article originally appeared on Engadget at https://www.engadget.com/suicide-squad-kill-the-justice-league-pulled-offline-after-a-bizarre-game-beating-bug-161955046.html?src=rss