logo

Online ransomware decryptor helps recover partially encrypted files

ID: bdb90b5a-65c8-5bde-9fad-1131186d41ae

STIX ID: report--bdb90b5a-65c8-5bde-9fad-1131186d41ae

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-01-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CyberArk released an online version of White Phoenix, an open-source decryptor that attempts to recover files partially encrypted by ransomware families using intermittent encryption (e.g., BlackCat/ALPHV, Play, Qilin/Agenda, BianLian, DarkBit); it supports common document and archive formats (PDF, Word, Excel, ZIP, PowerPoint) with a 10 MB upload limit, can rebuild files by concatenating unencrypted segments and reversing simple obfuscation, but has limitations and sensitive files are recommended to be processed locally via the GitHub release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.