Avast veröffentlicht kostenloses Entschlüsselungsprogramm für DoNex-Ransomware und frühere Varianten

Teilen:

Antivirus company Avast have discovered a weakness in the cryptographic scheme of the DoNex ransomware family and released a decryptor so victims can recover their files for free.

The company says it has been working with law enforcement to privately provide the decryptor to DoNex ransomware victims since March 2024. Cybersecurity vendors commonly distribute decryptors in this manner to prevent the threat actors from learning about the bug and fixing it.

The flaw was publicly disclosed at last month’s Recon 2024 cybersecurity conference, so Avast has decided to release the decryptor.

Decrypting DoNex

DoNext is a 2024 rebrand of DarkRace, which was, in turn, a 2023 rebrand of the Muse ransomware, first released in April 2022.

The flaw discovered by Avast impacts all past DoNex ransomware family variants, including a fake Lockbit 3.0-branded variant used under the ‘Muse’ name in November 2022.

Avast says that based on its telemetry, DoNex’s recent activity was concentrated in the United States, Italy, and Belgium but had a worldwide reach.

Weakness in cryptography

During the DoNex ransomware’s execution, an encryption key is generated using the ‘CryptGenRandom()’ function, initializing a ChaCha20 symmetric key used to encrypt the target’s files.

After the file encryption phase, the ChaCha20 key is encrypted using RSA-4096 and appended to the end of each file.

Avast has not elaborated on where the weakness lies, so it might concern key reuse, predictable key generation, improper padding, or other problems.

It is worth noting that DoNex uses intermittent encryption for files larger than 1MB. This tactic increases speed when encrypting files but introduces weaknesses that can be leveraged to restore encrypted data without paying a ransom.

Avast’s decryptor for DoNex and past variants is available from here. Users are recommended to pick the 64-bit version, as the password-cracking step requires a lot of memory.

The decryptor tool needs to be executed by an admin user, requiring a pair of encrypted and original files.

Avast advises users to provide the largest possible file as an “example” file, as it will determine the maximum file size that can be decrypted using the tool.

Make sure to backup your encrypted files before attempting decryption using the tool, as there’s always the possibility of something going wrong and corrupting those files beyond recovery.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:04 pm, Jan. 19, 2025
Wetter-Symbol 3°C
L: 1° | H: 3°
overcast clouds
Luftfeuchtigkeit: 86 %
Druck: 1020 mb
Wind: 4 mph WSW
Windböe: 6 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:55 am
Sonnenuntergang: 4:26 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
1° | 3°°C 0 mm 0% 6 mph 88 % 1019 mb 0 mm/h
Di. Jan. 21 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 4 mph 95 % 1017 mb 0 mm/h
Mi. Jan. 22 9:00 pm
Wetter-Symbol
4° | 6°°C 1 mm 100% 6 mph 99 % 1009 mb 0 mm/h
Do. Jan. 23 9:00 pm
Wetter-Symbol
4° | 8°°C 1 mm 100% 14 mph 89 % 1006 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
4° | 11°°C 1 mm 100% 25 mph 93 % 1007 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 2 mph 86 % 1019 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 2 mph 80 % 1019 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 4°°C 0 mm 0% 1 mph 76 % 1019 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 72 % 1019 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 5 mph 70 % 1019 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 6 mph 76 % 1017 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 82 % 1018 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 4 mph 88 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,182.10
-1.14%
Ethereum(ETH)
€3,159.78
-0.96%
XRP(XRP)
€2.95
-6.02%
Fesseln(USDT)
€0.97
-0.02%
Solana(SOL)
€244.97
-1.00%
Dogecoin(DOGE)
€0.354574
-7.07%
USDC(USDC)
€0.97
0.03%
Shiba Inu(SHIB)
€0.000020
-8.99%
Pepe(PEPE)
€0.000016
-10.57%
Peanut das Eichhörnchen(PNUT)
€0.436988
-11.65%
Nach oben scrollen