logo

Free Rhysida ransomware decryptor for Windows exploits RNG flaw

ID: 0e92f85e-dd55-5054-9072-4563047a8087

STIX ID: report--0e92f85e-dd55-5054-9072-4563047a8087

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-02-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Rhysida ransomware encryption flaw disclosed — free Windows decryptor available.** South Korean researchers and KISA published a technical paper and a Windows decryptor after finding that Rhysida's CSPRNG seed is time-derived and guessable, allowing recovery of the encryption key/IV to decrypt intermittently-encrypted file segments; the flaw had been privately used by responders since mid-2023 but is now public, though the decryptor only applies to the Windows encryptor (not ESXi or PowerShell variants).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.