logo

Avast releases free decryptor for DoNex ransomware and past variants

ID: 5e85c6f2-7bf5-505f-a3e4-f72616d835ca

STIX ID: report--5e85c6f2-7bf5-505f-a3e4-f72616d835ca

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-07-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Avast discovered a cryptographic weakness in the DoNex ransomware family (formerly DarkRace/Muse) and has released a decryptor that can recover files from all past DoNex variants; the report details DoNex's encryption method (ChaCha20 key generation via CryptGenRandom and RSA-4096-wrapped keys), affected geographies, and guidance for using the decryptor (requires admin privileges and a matching encrypted/original file pair).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.