New Black Basta decryptor exploits ransomware flaw to recover files
ID: 27ec7b8e-8cdb-54dc-9fcf-387eaadaf5f6
STIX ID: report--27ec7b8e-8cdb-54dc-9fcf-387eaadaf5f6
Feed Name: Bleeping Computer
Threat Score
SRLabs published a 'Black Basta Buster' decryptor that exploits a flaw in Black Basta's XChaCha20-based encryption, enabling recovery of many files encrypted by versions from November 2022 until the bug was patched a week ago; the report explains recovery limits (file-size dependent), how the keystream can be recovered from zero-byte regions (e.g., virtual disk images), and provides context on Black Basta's criminal activity and notable victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
