Avast releases free decryptor for DoNex ransomware and past variants
ID: 5e85c6f2-7bf5-505f-a3e4-f72616d835ca
STIX ID: report--5e85c6f2-7bf5-505f-a3e4-f72616d835ca
Feed Name: Bleeping Computer
Threat Score
Avast discovered a cryptographic weakness in the DoNex ransomware family (formerly DarkRace/Muse) and has released a decryptor that can recover files from all past DoNex variants; the report details DoNex's encryption method (ChaCha20 key generation via CryptGenRandom and RSA-4096-wrapped keys), affected geographies, and guidance for using the decryptor (requires admin privileges and a matching encrypted/original file pair).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
