logo

Korean eggheads crack Rhysida ransomware and release free decryptor tool

ID: 63411648-9546-5376-bb2b-2452923b2744

STIX ID: report--63411648-9546-5376-bb2b-2452923b2744

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-02-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Researchers in South Korea found an implementation vulnerability in Rhysida ransomware's use of LibTomCrypt's ChaCha20-based CSPRNG (seeded by a 32-bit execution time) that allowed them to regenerate the RNG state, derive per-file AES-256 keys, and produce a working decryptor; KISA is distributing the free recovery tool. The report also notes Rhysida's intermittent partial-file encryption, keys wrapped with a hardcoded RSA public key, its targeting of sectors such as education, healthcare, manufacturing, IT and government, and advises wiping compromised systems even after successful decryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.