HomeSecurityDecrypt Linux/ESXi Akira Ransomware files without paying ransom

Decrypt Linux/ESXi Akira Ransomware files without paying ransom

A cybersecurity researcher has managed to break the encryption used by the Linux/ESXI variant of the Akira ransomware, allowing data to be restored without the need to pay the ransom.

See also: New Akira Linux Ransomware Attacks VMware ESXi Servers

Akira Ransomware

The discovery exploits a critical weakness in the ransomware's encryption methodology. According to the researcher, the malware uses the current time in nanoseconds as a "seed" for the encryption process, making it theoretically vulnerable to brute-force attacks.

The Akira ransomware variant, identified by the hash bcae978c17bcddc0bf6419ae978e3471197801c36f73cff2fc88cecbe3d88d1a, uses an advanced encryption system that leverages four different timestamps, each with a resolution of nanoseconds.

This complexity initially made decryption seemingly impossible, but persistence and computing power eventually prevailed. The researcher has published the full source code and methodology on GitHub, offering a potential lifeline for organizations affected by this particular ransomware variant that has been active since late 2023.

See also: November 2024: Increased Akira & RansomHub ransomware activity

The researcher reverse-analyzed the ransomware code and found that it uses the Yarrow256 random number generator , which is fed with timestamp values. The ransomware uses this function to generate keys for the KCipher2 and Chacha8 encryption algorithms .

Decrypt Linux/ESXi Akira Ransomware files without paying ransom

To break the encryption, the researcher developed a brute-force tool optimized for CUDA, which takes advantage of high-performance GPUs.

After extensive optimization, the system achieved approximately 1.5 billion encryption attempts per second on an RTX 3090 GPU, while the RTX 4090 offered even better performance, achieving 2.3 times.

As ransomware evolves, this work highlights the ongoing arms race between attackers and defenders. Each successful decryption without payment undermines the ransomware business model, potentially discouraging future attacks.

See also: Akira Ransomware: 30 victims in one day on leak site

Protecting yourself from ransomware requires a combination of security strategies and best practices. Here are some steps you can take to protect yourself from ransomware:

  • Software Updates: Make sure to keep your operating system, applications, and antivirus up to date.
  • Use a reliable antivirus: Install and use a reliable antivirus that offers real-time protection.
  • Secure Backup: Regularly back up your important files.
  • Avoid clicking on suspicious links: Do not open emails from unknown senders and do not click on suspicious links or attachments.
  • User education and awareness: If you work in a team or organization, educate users on recognizing malicious messages or websites and the importance of security.

Source: cybersecuritynews

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS