Free Decryptor Released for Black Basta and Babuk's Tortilla Ransomware Victims
ID: 436ae863-8742-5301-8573-d08406b67b43
STIX ID: report--436ae863-8742-5301-8573-d08406b67b43
Feed Name: The Hacker News
Threat Score
Cisco Talos and Avast released an updated decryptor enabling victims of the Tortilla (Babuk-derived) ransomware campaign to recover files; Talos' intelligence sharing aided a law enforcement arrest. The report notes Tortilla’s use of ProxyShell Exchange exploits, lists other Babuk-derived ransomware families, and references SRLabs' Black Basta decryptor research which exploited a cryptographic weakness but was later mitigated by the ransomware authors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
