Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Free decryptor released for Black Basta and Babuk’s Tortilla ransomware victims
    Cyber Security

    Free decryptor released for Black Basta and Babuk’s Tortilla ransomware victims

    techempireBy techempire2 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 10, 2024Editorial DepartmentRansomware/Data Security

    Free ransomware decryptor

    Cisco Talos has released a decryptor for the Tortilla variant of the Babuk ransomware, allowing victims of the malware attack to regain access to their files.

    The cybersecurity company said threat intelligence it shared with Dutch law enforcement authorities made it possible to arrest the threat actors behind the operation.

    The encryption key has also been shared with Avast, which previously released a decryptor for the Babuk ransomware after the source code was leaked in September 2021.The updated decryptor can be accessed here [EXE file].

    Internet security

    “One private key is used for all victims of the Tortilla threat actor,” Avast noted. “This makes the decryptor update particularly useful, as all victims of the campaign can use it to decrypt their files.”

    Talos first disclosed the Tortilla campaign in November 2021, an attack that exploited a ProxyShell flaw in Microsoft Exchange servers to deliver ransomware in victim environments.

    Free ransomware decryptor

    Tortilla is one of many ransomware variants whose file-encrypting malware is based on leaked Babuk source code. These include Rook, Night Sky, Pandora, Nokoyawa, Cheerscrypt, AstraLocker 2.0, ESXiArgs, Rorschach, RTM Locker and RA Group.

    German cybersecurity company Security Research Labs (SRLabs) has released a Black Basta ransomware decryptor called Black Basta Buster, which exploits encryption vulnerabilities to partially or fully recover files.

    Internet security

    “The file can be recovered if the 64 encrypted bytes of plaintext are known,” SRLabs said. “Whether a file is fully or partially recoverable depends on the size of the file.”

    “Files smaller than 5000 bytes cannot be recovered. For files between 5000 bytes and 1GB, full recovery is possible. For files larger than 1GB, the first 5000 bytes will be lost, but the rest can be recovered.”

    Bleeping Computer reported late last month that Black Basta developers had fixed the issue, preventing the tool from handling newer infections.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.