logo

Free Decryptor Released for Black Basta and Babuk's Tortilla Ransomware Victims

ID: 436ae863-8742-5301-8573-d08406b67b43

STIX ID: report--436ae863-8742-5301-8573-d08406b67b43

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-01-10

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Cisco Talos and Avast released an updated decryptor enabling victims of the Tortilla (Babuk-derived) ransomware campaign to recover files; Talos' intelligence sharing aided a law enforcement arrest. The report notes Tortilla’s use of ProxyShell Exchange exploits, lists other Babuk-derived ransomware families, and references SRLabs' Black Basta decryptor research which exploited a cryptographic weakness but was later mitigated by the ransomware authors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.