Rhysida Ransomware Cracked, Free Decryption Tool Released
ID: 9c1676e2-21af-5167-a691-46c892a23829
STIX ID: report--9c1676e2-21af-5167-a691-46c892a23829
Feed Name: The Hacker News
Researchers from Kookmin University and KISA disclosed an implementation vulnerability in Rhysida ransomware that enabled recovery of the encryption seed and successful decryption of affected Windows PE victims; KISA is distributing a recovery tool. The analysis details use of a ChaCha20-based CSPRNG (LibTomCrypt), how per-file random generation and multi-threaded encryption produced a recoverable seed and file order, and notes the technique does not apply to ESXi or PowerShell variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
