Security researchers have published a new suite of tools designed to help victims of the prolific Black Basta ransomware recover their files.
Berlin-based Security Research Labs revealed in a recent GitHub post that the tools exploit a weakness in the encryption algorithm.
Black Basta uses a ChaCha keystream to XOR encrypt 64-byte-long chunks of victim files.
The tools work specifically when Black Basta encrypts files containing only zeros, which is why it mainly works only for larger files.
The decryption tools will only work for the Black Basta ransomware variant used in around April 2023, the researchers continued.
Black Basta is one of the most successful ransomware-as-a-service operations around, having generated over $100m in revenue since April 2022.
Its developers are suspected of links to the now-defunct Conti group and Qakbot malware.
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Tue, 02 Jan 2024 09:35:40 +0000