Kaspersky has released a decryptor for Fonix ransomware (XONIF) that allows victims to recover their encrypted files for free. Fonix ransomware, also known as Xinof and FonixCrypter, began to spread across the threat landscape in June 2020, having significantly increased the number of its victims since November of that year. Now, the decryptor is here to help victims.

On January 29, one of the administrators of the Fonix ransomware tweeted that they have stopped the ransomware “operation” and have released the master decryption key. Specifically, the Fonix ransomware gang member stated the following:
“I am an admin of the Fonix team. You know about the Fonix team but it has come to an end. We need to use our skills in positive ways and help others. Also, the ransomware source is completely deleted, but some of the team members disagree with closing the project, like the admin of the Telegram who is trying to scam people on the Telegram channel by selling fake sources and data. Anyway, the main admin decided to leave all previous work aside and decrypt all infected systems free of charge. “- FonixTeam”.

The administrator of the Fonix ransomware told BleepingComputer that the gang had encrypted around 5,000-6,000 systems throughout its existence.
Shortly after the decryptor was published, Michael Gillespie confirmed to BleepingComputer that the key was valid and could be used to decrypt a victim's files.
Victims of Fonix ransomware can decrypt their files for free using an updated version of Kaspersky’s RakhniDecryptor . First, they need to download the decryptor to a device with encrypted files and launch the program. They will be asked to accept a license agreement and the main interface will appear .

When they are ready to decrypt their files, they should click on the “Start Scan” button and Kaspersky’s decryptor will ask them to select an encrypted file. Once selected, the decryptor will search for their decryption key and when it is found, they should start decrypting their files.
Finally, after decrypting their files and verifying that they open correctly, ransomware victims can delete the remaining encrypted files.
