logo

A Ransomware Reversal: Sicarii Can't Decrypt (But Halcyon Can)

ID: 617fa342-2d38-5982-b4be-64162e4f89af

STIX ID: report--617fa342-2d38-5982-b4be-64162e4f89af

Feed Name: Halcyon Blog

Threat Score
70/100

Date Published: 2026-02-10

Date Updated: 2026-04-28

...
...

Halcyon published analysis showing a coding defect in the Sicarii ransomware encryptor that caused encrypted files to become irrecoverable even if victims paid ransom; Halcyon’s key-material capture technology, however, was able to intercept keys during encryption and fully restore affected files. Sicarii has since released fixes, illustrating rapid attacker iteration, while the report underscores the importance of anti-ransomware platforms and validated recovery options over relying on ransom payments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.