logo

Rhysida Ransomware Cracked, Free Decryption Tool Released

ID: 9c1676e2-21af-5167-a691-46c892a23829

STIX ID: report--9c1676e2-21af-5167-a691-46c892a23829

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-02-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers from Kookmin University and KISA disclosed an implementation vulnerability in Rhysida ransomware that enabled recovery of the encryption seed and successful decryption of affected Windows PE victims; KISA is distributing a recovery tool. The analysis details use of a ChaCha20-based CSPRNG (LibTomCrypt), how per-file random generation and multi-threaded encryption produced a recoverable seed and file order, and notes the technique does not apply to ESXi or PowerShell variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.