Avast veröffentlicht kostenloses Entschlüsselungsprogramm für DoNex-Ransomware und frühere Varianten

Teilen:

Antivirus company Avast have discovered a weakness in the cryptographic scheme of the DoNex ransomware family and released a decryptor so victims can recover their files for free.

The company says it has been working with law enforcement to privately provide the decryptor to DoNex ransomware victims since March 2024. Cybersecurity vendors commonly distribute decryptors in this manner to prevent the threat actors from learning about the bug and fixing it.

The flaw was publicly disclosed at last month’s Recon 2024 cybersecurity conference, so Avast has decided to release the decryptor.

Decrypting DoNex

DoNext is a 2024 rebrand of DarkRace, which was, in turn, a 2023 rebrand of the Muse ransomware, first released in April 2022.

The flaw discovered by Avast impacts all past DoNex ransomware family variants, including a fake Lockbit 3.0-branded variant used under the ‘Muse’ name in November 2022.

Avast says that based on its telemetry, DoNex’s recent activity was concentrated in the United States, Italy, and Belgium but had a worldwide reach.

Weakness in cryptography

During the DoNex ransomware’s execution, an encryption key is generated using the ‘CryptGenRandom()’ function, initializing a ChaCha20 symmetric key used to encrypt the target’s files.

After the file encryption phase, the ChaCha20 key is encrypted using RSA-4096 and appended to the end of each file.

Avast has not elaborated on where the weakness lies, so it might concern key reuse, predictable key generation, improper padding, or other problems.

It is worth noting that DoNex uses intermittent encryption for files larger than 1MB. This tactic increases speed when encrypting files but introduces weaknesses that can be leveraged to restore encrypted data without paying a ransom.

Avast’s decryptor for DoNex and past variants is available from here. Users are recommended to pick the 64-bit version, as the password-cracking step requires a lot of memory.

The decryptor tool needs to be executed by an admin user, requiring a pair of encrypted and original files.

Avast advises users to provide the largest possible file as an “example” file, as it will determine the maximum file size that can be decrypted using the tool.

Make sure to backup your encrypted files before attempting decryption using the tool, as there’s always the possibility of something going wrong and corrupting those files beyond recovery.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:14 pm, Juni 18, 2025
Wetter-Symbol 25°C
L: 24° | H: 26°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 50 %
Druck: 1025 mb
Wind: 6 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 35%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:42 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
24° | 26°°C 0 mm 0% 8 mph 54 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 30°°C 0 mm 0% 11 mph 71 % 1026 mb 0 mm/h
Fr. Juni 20 10:00 pm
Wetter-Symbol
17° | 28°°C 0 mm 0% 11 mph 72 % 1026 mb 0 mm/h
Sa. Juni 21 10:00 pm
Wetter-Symbol
17° | 32°°C 0 mm 0% 10 mph 60 % 1022 mb 0 mm/h
So. Juni 22 10:00 pm
Wetter-Symbol
21° | 32°°C 0.28 mm 28% 15 mph 57 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 5 mph 50 % 1025 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
26° | 28°°C 0 mm 0% 8 mph 46 % 1025 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 8 mph 43 % 1024 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 4 mph 54 % 1025 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 2 mph 64 % 1025 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 1 mph 71 % 1025 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 2 mph 65 % 1026 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
25° | 25°°C 0 mm 0% 3 mph 46 % 1026 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,902.18
-1.48%
Ethereum(ETH)
€2,177.42
-2.16%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.86
-3.71%
Solana(SOL)
€127.09
-3.38%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.145768
-2.38%
Shiba Inu(SHIB)
€0.000010
-1.77%
Pepe(PEPE)
€0.000009
-4.07%
Nach oben scrollen