Security researchers have created a decryption tool for the Black Basta ransomware, allowing victims to recover files for free. The researchers exploited a flaw in the ransomware to create the decryptor.

It appears that victims of Black Basta from November 2022 to last month can use the tool to recover files their. However, according to BleepingComputer, Black Basta developers fixed the bug about a week ago, so the decryption tool will not be effective in subsequent attacks.
Black Basta ransomware: What flaw did the researchers exploit?
The “ Black Basta Buster ” decryption tool was created by Security Research Labs (SRLabs) , which found a weakness in the ransomware’s encryption algorithm.
“ Our analysis suggests that files can be recovered if the plaintext of the 64 encrypted bytes is known. Whether a file is fully or partially recoverable depends on the size of the file ,” the researchers explain .
“Files smaller than 5000 bytes cannot be recovered. For files between 5000 bytes and 1 GB, full recovery is possible. For files larger than 1 GB, the first 5000 bytes will be lost but the rest can be recovered“.
See also: Chinese hackers create ransomware via ChatGPT
BleepingComputer says that when Black Basta ransomware encrypts a file, it XORs the contents using a 64-byte keystream created using the XChaCha20. However, when a stream cipher is used to encrypt a file whose bytes contain only zeros, the XOR key itself is written to the file, allowing the encryption key to be recovered.
According to ransomware expert Michael Gillespie, the Black Basta ransomware reused the same keystream during encryption, resulting in all 64-byte chunks of data containing only zeros being converted into a 64-byte symmetric key. This key can then be extracted and used to decrypt the entire file.
While decryption of smaller files may not be possible, larger files such as virtual machine disks can usually be decrypted, as they contain a large number of “zero-byte” segments.
Black Basta Buster: The useful decryption tool
SRLabs has released the decryption tool for Black Basta ransomware, consisting of a collection of python scripts that help recover.
The researchers also created a script called “decryptauto.py” that attempts to automatically retrieve the key and then use it to decrypt the file.
As we mentioned earlier, the tool is only effective for victims affected from November 2022 until about a week ago.
The decryptor only works on one file at a time, so to recover an entire folder, you will need a shell script or the 'find' command.
find . -name “*.4xw1woqp0” -exec ../black-basta-buster/decryptauto.py “{}” \;
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Black Basta ransomware: A major threat
The Black Basta ransomware gang began operating in April 2022. By June 2022, it had partnered with the QBot (QakBot) malware operation to remotely access corporate networks.
See also: Ministry of Justice: Disrupts the BlackCat Ransomware Gang
The Black Basta gang carries out attacks double extortion. It steals data from systems, encrypts it, and then threatens to leak it.
The group is responsible for a series of attacks, including those on Capita, the American Dental Association, Sobeys, Knauf, and Yellow Pages Canada. Most recently, the ransomware operation targeted the Toronto Public Library, Canada's largest public library system

What are the consequences of ransomware for companies and individuals?
The consequences of ransomware for companies and individuals can be far-reaching and devastating. At its core, ransomware is a type of malware that encrypts a data , making it inaccessible without the necessary decryption key.
For companies, this can mean the loss of valuable data, disruption to operations, and loss of customer trust. In addition, restoring systems can be costly and time-consuming.
For individuals, ransomware can lead to the loss of personal data, such as photos, documents, and other files. Furthermore, paying the ransom does not always guarantee the restoration of data.
See also: DragonForce Ransomware: Attacked Yakult Australia
Ransomware attacks can also have psychological consequences for victims, as they may feel violated, powerless, and insecure. This can lead to stress and anxiety, especially if the data lost was valuable or sensitive.
Finally, ransomware can have significant legal consequences. Companies that fall victim to ransomware can face lawsuits if they fail to protect their customers' data.
Source: www.bleepingcomputer.com
