Avast releases free decryptor for DoNex ransomware and past variants

Share:

Antivirus company Avast have discovered a weakness in the cryptographic scheme of the DoNex ransomware family and released a decryptor so victims can recover their files for free.

The company says it has been working with law enforcement to privately provide the decryptor to DoNex ransomware victims since March 2024. Cybersecurity vendors commonly distribute decryptors in this manner to prevent the threat actors from learning about the bug and fixing it.

The flaw was publicly disclosed at last month’s Recon 2024 cybersecurity conference, so Avast has decided to release the decryptor.

Decrypting DoNex

DoNext is a 2024 rebrand of DarkRace, which was, in turn, a 2023 rebrand of the Muse ransomware, first released in April 2022.

The flaw discovered by Avast impacts all past DoNex ransomware family variants, including a fake Lockbit 3.0-branded variant used under the ‘Muse’ name in November 2022.

Avast says that based on its telemetry, DoNex’s recent activity was concentrated in the United States, Italy, and Belgium but had a worldwide reach.

Weakness in cryptography

During the DoNex ransomware’s execution, an encryption key is generated using the ‘CryptGenRandom()’ function, initializing a ChaCha20 symmetric key used to encrypt the target’s files.

After the file encryption phase, the ChaCha20 key is encrypted using RSA-4096 and appended to the end of each file.

Avast has not elaborated on where the weakness lies, so it might concern key reuse, predictable key generation, improper padding, or other problems.

It is worth noting that DoNex uses intermittent encryption for files larger than 1MB. This tactic increases speed when encrypting files but introduces weaknesses that can be leveraged to restore encrypted data without paying a ransom.

Avast’s decryptor for DoNex and past variants is available from here. Users are recommended to pick the 64-bit version, as the password-cracking step requires a lot of memory.

The decryptor tool needs to be executed by an admin user, requiring a pair of encrypted and original files.

Avast advises users to provide the largest possible file as an “example” file, as it will determine the maximum file size that can be decrypted using the tool.

Make sure to backup your encrypted files before attempting decryption using the tool, as there’s always the possibility of something going wrong and corrupting those files beyond recovery.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:53 am, Jul 11, 2025
weather icon 18°C
L: 17° | H: 19°
scattered clouds
Humidity: 80 %
Pressure: 1021 mb
Wind: 6 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 45%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:56 am
Sunset: 9:15 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 19°°C 0 mm 0% 8 mph 80 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 7 mph 71 % 1015 mb 0 mm/h
Mon Jul 14 10:00 pm
weather icon
18° | 28°°C 1 mm 100% 15 mph 84 % 1016 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
14° | 20°°C 1 mm 100% 14 mph 81 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
16° | 18°°C 0 mm 0% 3 mph 80 % 1021 mb 0 mm/h
Today 7:00 am
weather icon
18° | 19°°C 0 mm 0% 2 mph 76 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
24° | 27°°C 0 mm 0% 2 mph 57 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 3 mph 32 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
32° | 32°°C 0 mm 0% 4 mph 26 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
30° | 30°°C 0 mm 0% 6 mph 29 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 49 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0 mm 0% 5 mph 57 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,548.70
4.71%
Ethereum(ETH)
€2,531.28
6.50%
Tether(USDT)
€0.85
-0.02%
XRP(XRP)
€2.20
6.50%
Solana(SOL)
€141.00
4.20%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.169176
9.42%
Shiba Inu(SHIB)
€0.000012
9.17%
Pepe(PEPE)
€0.000011
15.00%
Peanut the Squirrel(PNUT)
€0.247974
22.95%
Scroll to Top