Online ransomware decryptor helps recover partially encrypted files
ID: bdb90b5a-65c8-5bde-9fad-1131186d41ae
STIX ID: report--bdb90b5a-65c8-5bde-9fad-1131186d41ae
Feed Name: Bleeping Computer
CyberArk released an online version of White Phoenix, an open-source decryptor that attempts to recover files partially encrypted by ransomware families using intermittent encryption (e.g., BlackCat/ALPHV, Play, Qilin/Agenda, BianLian, DarkBit); it supports common document and archive formats (PDF, Word, Excel, ZIP, PowerPoint) with a 10 MB upload limit, can rebuild files by concatenating unencrypted segments and reversing simple obfuscation, but has limitations and sensitive files are recommended to be processed locally via the GitHub release.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
