A Spanish student this week released a free decryption utility that can help victims of Avaddon ransomware recover their files for free. Javier Yuste, a student at the Rey Juan Carlos University in Madrid, shared AvaddonDecrypter on GitHub , which only works in cases where victims have not turned off their computers .
The tool works by dumping the RAM of an infected system and searching the memory contents for data that could be used to recover the ransomware's original encryption key. If enough information is recovered, the tool can then be used to decrypt files, as well as help victims recover from attacks , without having to pay a ransom to the hackers.

It should be noted, however, that while the release of the tool will likely help existing Avaddon victims, it will not help companies that are falling victim to new ransomware attacks. This is because the release of the tool has not gone unnoticed. In a forum post on February 10, the Avaddon gang reported that they learned about the Yuste decryptor and have already deployed updates to code , thus negating the tool’s capabilities.

The Avaddon gang's reaction follows that of the hackers who developed the DarkSide ransomware, who also reacted to the release of a similar decryptor for their own case in January.

Therefore, the release of both decryption utilities had a very limited impact. While some victims were able to decrypt their files, once the existence of the decryption tools was made public, ransomware gangs analyzed how the tools worked and patched their ransomware code within a few days.
As ZDNet reports, the publication of these two tools, combined with a blog post shared by Dutch security firm Eye Control showing how victims could recover from Data Doctor ransomware attacks, has reignited, once again, a long-standing debate in the cybersecurity about how decryption utilities should be handled and communicated to victims.
Many prominent security researchers with a long history of helping ransomware victims since the mid-2010s have re-emerged in the past couple of months, highlighting the fact that decryption utilities that exploit flaws should remain private and distributed to victims through non-public channels, rather than being advertised online.
