logo

New Black Basta decryptor exploits ransomware flaw to recover files

ID: 27ec7b8e-8cdb-54dc-9fcf-387eaadaf5f6

STIX ID: report--27ec7b8e-8cdb-54dc-9fcf-387eaadaf5f6

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2023-12-30

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

SRLabs published a 'Black Basta Buster' decryptor that exploits a flaw in Black Basta's XChaCha20-based encryption, enabling recovery of many files encrypted by versions from November 2022 until the bug was patched a week ago; the report explains recovery limits (file-size dependent), how the keystream can be recovered from zero-byte regions (e.g., virtual disk images), and provides context on Black Basta's criminal activity and notable victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.