HomeSecurityBlackByte ransomware decryptor for free file recovery

BlackByte ransomware decryptor for file recovery for free

A free BlackByte ransomware decryptor has been released, allowing previous victims to recover their files for free.

When executed, most ransomware generates a unique encryption key per file or a single key per machine known as session keys that are used to encrypt a victim's device.

See Also: Information Security Engineer wanted for a large ISP provider – Send CV

BlackByte ransomware decryptor for file recovery for free
BlackByte ransomware decryptor for file recovery for free

These keys are then encrypted with a public RSA key and appended to the end of an encrypted file or ransom note. This encrypted key can only be decrypted by the associated private decryption key known only to the hackers who choose to give it to victims once the required ransom is paid.

In a report by Trustwave, researchers explain that the BlackByte ransomware downloaded a file called “forest.png” from a remote website that was under the control of the hackers. While this file is named to appear as an image file, it actually contains the AES encryption key used to encrypt a device.

See Also: Apple "Unleashed": What was presented at the company's event

As BlackByte uses AES symmetrical encryption, the same key is used for both encrypting and decrypting files.

One apt observation from Trustwave is that the hackers were reusing the same forest.png file for multiple victims. Since the same “raw” encryption key was being reused, the security firm thought it could use that key to create a decryptor that would recover a victim’s files for free.

However, there are always disadvantages when releasing free decryptors, such as hackers being immediately notified of the existence of "bugs" in their programs, which they take care to fix immediately.

See Also: Facebook – Is the well-known social media company changing its name?

BlackByte ransomware decryptor for file recovery for free
BlackByte ransomware decryptor for file recovery for free

The report and Trustwave's decryptor did not go unnoticed by the ransomware's creators, who warned that more than one key had been used and that using the decryptor with the wrong key would destroy a victim's files.

If you have fallen victim to BlackByte and want to use Trustwave's decryptor, you will need to download the source code from Github and compile it yourself.

See Also: China tested a hypersonic missile in orbit - The US is on alert!

BlackByte is a ransomware operation that slowly began targeting corporate victims worldwide in early July 2021.

While BlackByte is not as active as other ransomware operations, it has successfully carried out many attacks worldwide and should be taken seriously.

With information from bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS