Avast secretly gave DoNex ransomware decryptors to victims before crims vanished
ID: f7014a3a-7d3c-5c94-bf53-bc028586351e
STIX ID: report--f7014a3a-7d3c-5c94-bf53-bc028586351e
Feed Name: The Register (Security)
Avast discovered a crypto flaw in DoNex ransomware that allowed it to quietly supply decryptors to victims since March and then publish a public decryptor after the group's dark-web page was taken down; DoNex uses CryptGenRandom() to seed ChaCha20 for file encryption with RSA-4096-encrypted symmetric keys and performs full or intermittent encryption depending on file size, and appears to be a succession of low-novelty rebrands (Muse, DarkRace, DoNex) targeting several countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
