Tech

New version of LeChiffre ransomware

A seemingly new version of LeChiffre ransomware showed up on a customer’s site. The extension ends with AHGIDC_LeChiffre. Emsisoft and nomoreransom did not recognise the encryption, and I could not find out how did it get in. The link to the infected file:https://leitwerk.badenbox.de/s/aRWAGgjCSyZnFKR.
Any advice for this one or a decoder recommendation?

Hello @Stripes

This is the latest link which could support you.