A cybersecurity researcher has managed to break the encryption used by the Linux/ESXI variant of the Akira ransomware, allowing data to be restored without the need to pay the ransom.
See also: New Akira Linux Ransomware Attacks VMware ESXi Servers

The discovery exploits a critical weakness in the ransomware's encryption methodology. According to the researcher, the malware uses the current time in nanoseconds as a "seed" for the encryption process, making it theoretically vulnerable to brute-force attacks.
The Akira ransomware variant, identified by the hash bcae978c17bcddc0bf6419ae978e3471197801c36f73cff2fc88cecbe3d88d1a, uses an advanced encryption system that leverages four different timestamps, each with a resolution of nanoseconds.
This complexity initially made decryption seemingly impossible, but persistence and computing power eventually prevailed. The researcher has published the full source code and methodology on GitHub, offering a potential lifeline for organizations affected by this particular ransomware variant that has been active since late 2023.
See also: November 2024: Increased Akira & RansomHub ransomware activity
The researcher reverse-analyzed the ransomware code and found that it uses the Yarrow256 random number generator , which is fed with timestamp values. The ransomware uses this function to generate keys for the KCipher2 and Chacha8 encryption algorithms .

To break the encryption, the researcher developed a brute-force tool optimized for CUDA, which takes advantage of high-performance GPUs.
After extensive optimization, the system achieved approximately 1.5 billion encryption attempts per second on an RTX 3090 GPU, while the RTX 4090 offered even better performance, achieving 2.3 times.
As ransomware evolves, this work highlights the ongoing arms race between attackers and defenders. Each successful decryption without payment undermines the ransomware business model, potentially discouraging future attacks.
See also: Akira Ransomware: 30 victims in one day on leak site
Protecting yourself from ransomware requires a combination of security strategies and best practices. Here are some steps you can take to protect yourself from ransomware:
- Software Updates: Make sure to keep your operating system, applications, and antivirus up to date.
- Use a reliable antivirus: Install and use a reliable antivirus that offers real-time protection.
- Secure Backup: Regularly back up your important files.
- Avoid clicking on suspicious links: Do not open emails from unknown senders and do not click on suspicious links or attachments.
- User education and awareness: If you work in a team or organization, educate users on recognizing malicious messages or websites and the importance of security.
Source: cybersecuritynews
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
