Reverse engineering and decrypting CyberArk vault credential files
ID: d0c97cb8-70a2-5a27-9bca-98fd577c1168
STIX ID: report--d0c97cb8-70a2-5a27-9bca-98fd577c1168
Feed Name: Fox-IT blog
Threat Score
This technical analysis demonstrates that CyberArk password-type .cred files use a recoverable custom key-derivation and AES encryption scheme based primarily on an AdditionalInformation field; the author reverse-engineered the algorithm, implemented a Python decryption tool, and recommends protecting credential files and using DPAPI protection—CyberArk subsequently released an update to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
