logo

Avast secretly gave DoNex ransomware decryptors to victims before crims vanished

ID: f7014a3a-7d3c-5c94-bf53-bc028586351e

STIX ID: report--f7014a3a-7d3c-5c94-bf53-bc028586351e

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2024-07-08

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Avast discovered a crypto flaw in DoNex ransomware that allowed it to quietly supply decryptors to victims since March and then publish a public decryptor after the group's dark-web page was taken down; DoNex uses CryptGenRandom() to seed ChaCha20 for file encryption with RSA-4096-encrypted symmetric keys and performs full or intermittent encryption depending on file size, and appears to be a succession of low-novelty rebrands (Muse, DarkRace, DoNex) targeting several countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.