logo

A tale of Phobos - how we almost cracked a ransomware using CUDA

ID: 57d2dc30-4c4d-56c7-a352-e0672d3089d5

STIX ID: report--57d2dc30-4c4d-56c7-a352-e0672d3089d5

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2023-02-23

Date Updated: 2026-04-19

Author: Jarosław Jedynak

...
...

This report analyzes the Phobos ransomware's weak key-schedule, demonstrates how that weakness can be exploited to recover keys, and documents a high-performance CUDA-based proof-of-concept decryptor (with source code). It explains the entropy analysis, brute-force optimizations, performance tuning (SHA-256 and AES on GPU), required assumptions (precise time, PID/TID knowledge), practical limitations, and includes the sample hash and repository for the PoC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.