Free Rhysida ransomware decryptor for Windows exploits RNG flaw
ID: 0e92f85e-dd55-5054-9072-4563047a8087
STIX ID: report--0e92f85e-dd55-5054-9072-4563047a8087
Feed Name: Bleeping Computer
**Rhysida ransomware encryption flaw disclosed — free Windows decryptor available.** South Korean researchers and KISA published a technical paper and a Windows decryptor after finding that Rhysida's CSPRNG seed is time-derived and guessable, allowing recovery of the encryption key/IV to decrypt intermittently-encrypted file segments; the flaw had been privately used by responders since mid-2023 but is now public, though the decryptor only applies to the Windows encryptor (not ESXi or PowerShell variants).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
