Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    46 Important Account-Based Marketing Statistics for the Modern Marketer

    Motion Picture Association will work with Congress to start blocking piracy websites in the United States

    Excellent Support Guide: Unlock Cloud Success

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Rhysida ransomware cracked!Free decryption tool released
    Cyber Security

    Rhysida ransomware cracked!Free decryption tool released

    techempireBy techempire1 Comment2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    This is good news for organizations that fell victim to the notorious Rhysida ransomware.

    A group of South Korean security researchers have discovered a vulnerability in the notorious ransomware. The vulnerability provides a way to decrypt encrypted archives.

    In a technical paper about their findings, Kookmin University researchers described how they exploited an implementation flaw in Rhysida’s code to regenerate its encryption keys.

    “The Rhysida ransomware uses a secure random number generator to generate encryption keys and subsequently encrypt the data. However, there is an implementation vulnerability that allows us to regenerate the internal state of the random number generator during infection. We successfully decrypted the data Using a regenerated random number generator. To our knowledge, this is the first successful decryption of Rhysida ransomware.”

    In due course, the Rhysida ransomware recovery tool was developed and distributed to the public through the Korea Internet Security Agency (KISA).

    Instructions in English for using the decryption tool are also provided.

    Fortunately, for those who don’t understand Korean, we have English instructions on how to use the decryption tool.

    Unfortunately, disclosing the existence of ransomware recovery tools does come with a price. The release of the tool and the results published by the researchers will inevitably alert the malicious hackers behind Rhysida to its flaw and will almost certainly ensure that it is fixed.

    Ransomware researchers are faced with a dilemma. If they discover a flaw in ransomware that allows them to decrypt victim data, they must carefully consider whether to make it public.

    Announcing the flaw and recovery method can help hacked organizations understand there is a way to recover their material without paying a ransom.

    Advocacy helps spread the message that solutions are possible.

    But the presence of recovery tools may also prompt cybercriminals to repair their code, depriving victims of potential treatments. So, is it better not to announce the existence of recovery tools?

    This is not an easy question to answer.

    The Rhysida decryptor is just the latest in a series of ransomware recovery tools that have emerged in recent years, including utilities to help victims of Yanlouwang, MegaCortex, Akira, REvil and Conti versions.


    Editor’s Note: The opinions expressed in this guest author article are those of the contributor and do not necessarily reflect the views of Tripwire.

    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Reflections on research and personal experience

    15,000 accounts compromised by data breach

    Cybercriminal loses $12.5 billion amid wave of cryptocurrency investment scams

    Process Mining and Business Intelligence

    The psychology of artificial intelligence credibility

    Serious flaw found in WordPress plugin used by over 300,000 websites

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    46 Important Account-Based Marketing Statistics for the Modern Marketer

    Motion Picture Association will work with Congress to start blocking piracy websites in the United States

    Excellent Support Guide: Unlock Cloud Success

    A progressive and proven vision for digital transformation

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Embracer sells majority stake in Saber Interactive in deal worth approximately $500 million

    What they are and when to use them

    Why you should enter a business case competition

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.