In a major development in the fight against cybercrime, Japanese police have announced the release of a free decryption tool for the Phobos and 8Base ransomware, which have plagued businesses and individuals in recent years. The tool, according to confirmed tests by BleepingComputer, works successfully, allowing victims to recover their encrypted files without paying a ransom.

From 2018 to the present: The path of Phobos
The Phobos threat first appeared in December 2018 as a ransomware-as-a-service (RaaS), allowing hackers or groups (affiliates) to use it for their own attacks. In return, ransom payments were shared between the affiliates and the operators. While it did not attract the same publicity as other criminal groups, it remains one of the most widespread ransomware platforms in the world, with a plethora of attacks against organizations on a global scale.
See also: Q2 2025: Increased ransomware attacks in retail
In 2023, a new group of Phobos collaborators created the 8Base, using a modified Phobos encryptor and implementing a strategy double extortion: not only did they encrypt victims' files, but they also stole data, threatening to make it public.
Law enforcement operations are changing the landscape
In 2024, a Russian national, believed to be the administrator of the Phobos organization, was extradited from South Korea to the United States facing 13 cybercrime charges. Meanwhile, this year, a coordinated international operation seized 27 servers and led to the arrest of four suspects (also Russians) who are alleged to have played a central role in the 8Base operation.
It is believed that during this operation the Japanese authorities obtained technical information that allowed the development of the decryption tool for Phobos and 8Base ransomware.
The free tool: Where to find it and how it works
The decryption tool is available for free via:
- The official website of the Japanese police
- Europol 's NoMoreRansom platform
Europol and the FBI actively support it, confirming its credibility and legitimacy.
What does it support:
The tool covers encrypted files with the following extensions:
.phobos.8base.elbie.faust.LIZARD
However, the Authorities point out that other extensions may be supported, so testing is recommended even if the files have a different name.
See also: Authorities dismantle Diskstation ransomware gang
How is it used:
- Launch the tool and accept the license agreement.
- Enable support for long file names (if prompted).
- Specify the folder with the encrypted files and the output folder.
- Select "Decrypt" and wait for the process to complete.
- The program restores files while preserving the original folder structure.
BleepingComputer confirmed that the tool successfully decrypted 150 files affected by the LIZARD variant.

Technical obstacles: False positive detections from browsers
It is worth noting that when downloading the tool, some browsers such as Chrome and Firefox may falsely identify it as malware. This causes confusion for users, but, according to analysts, this is a false alarm. Security checks by independent media assure that the decryption tool for Phobos and 8Base ransomware does not contain malicious code and works as expected.
A ray of light for the victims
The release of the decryptor by the Japanese police and the support of international organizations such as Europol and the FBI is a positive development in the hard-fought fight against ransomware. For those affected by Phobos or 8Base, this tool represents a rare opportunity for recovery without financial cost.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Albemarle County hit by Ransomware attack
The success of the tool is an example of how collaboration between countries and organizations can bring substantial results in the field of cybersecurity.
Ransomware protection
The above tool helps businesses and individuals who have already been affected. But how can you prevent an attack in the first place?
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using email security solutions for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
Source: www.bleepingcomputer.com
