Dark Angels Exposed
ID: d525d967-41d4-501c-91d9-cf33c806efa4
STIX ID: report--d525d967-41d4-501c-91d9-cf33c806efa4
Feed Name: Zscaler Security Research Blog
This report analyzes Dark Angels’ file-encryption techniques: a Windows RTM/Babuk-derived variant that uses per-file Curve25519 keys + ECDH and ChaCha20 with public keys appended to file extensions (no footer), and a RagnarLocker-based Linux/ESXi variant that uses a per-system secp256k1 key, ECDH (libsecp256k1 custom hash) and AES-256-CBC with a 177-byte footer containing decryption parameters and configurable block-skip modes; the document describes encryption flows, footer structure, optimization for large files, and a Windows implementation flaw that can prevent recovery of partially encrypted files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
