'Black Basta Buster' Exploits Ransomware Bug for File Recovery
ID: 7c4b3d2d-2f8b-5347-be96-02e78070e6d8
STIX ID: report--7c4b3d2d-2f8b-5347-be96-02e78070e6d8
Feed Name: Dark Reading
Date Published: 2024-01-03
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
SRLabs published 'Black Basta Buster,' a decryptor that leverages a flaw in a specific Black Basta ransomware strain's ChaCha-based XOR encryption to allow partial recovery of encrypted files. Recovery requires knowing 64 plaintext bytes in the encrypted portions and works best for files 5,000 bytes–1GB (files >1GB will lose the first 5,000 bytes); the group patched the flaw in mid-December, so only victims infected before the fix (about 153 leaked victims in the affected window) may benefit. The report also reiterates standard defenses such as patching, hardening remote access, EDR/MDR, and offsite backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
