Avast veröffentlicht kostenloses Entschlüsselungsprogramm für DoNex-Ransomware und frühere Varianten

Teilen:

Antivirus company Avast have discovered a weakness in the cryptographic scheme of the DoNex ransomware family and released a decryptor so victims can recover their files for free.

The company says it has been working with law enforcement to privately provide the decryptor to DoNex ransomware victims since March 2024. Cybersecurity vendors commonly distribute decryptors in this manner to prevent the threat actors from learning about the bug and fixing it.

The flaw was publicly disclosed at last month’s Recon 2024 cybersecurity conference, so Avast has decided to release the decryptor.

Decrypting DoNex

DoNext is a 2024 rebrand of DarkRace, which was, in turn, a 2023 rebrand of the Muse ransomware, first released in April 2022.

The flaw discovered by Avast impacts all past DoNex ransomware family variants, including a fake Lockbit 3.0-branded variant used under the ‘Muse’ name in November 2022.

Avast says that based on its telemetry, DoNex’s recent activity was concentrated in the United States, Italy, and Belgium but had a worldwide reach.

Weakness in cryptography

During the DoNex ransomware’s execution, an encryption key is generated using the ‘CryptGenRandom()’ function, initializing a ChaCha20 symmetric key used to encrypt the target’s files.

After the file encryption phase, the ChaCha20 key is encrypted using RSA-4096 and appended to the end of each file.

Avast has not elaborated on where the weakness lies, so it might concern key reuse, predictable key generation, improper padding, or other problems.

It is worth noting that DoNex uses intermittent encryption for files larger than 1MB. This tactic increases speed when encrypting files but introduces weaknesses that can be leveraged to restore encrypted data without paying a ransom.

Avast’s decryptor for DoNex and past variants is available from here. Users are recommended to pick the 64-bit version, as the password-cracking step requires a lot of memory.

The decryptor tool needs to be executed by an admin user, requiring a pair of encrypted and original files.

Avast advises users to provide the largest possible file as an “example” file, as it will determine the maximum file size that can be decrypted using the tool.

Make sure to backup your encrypted files before attempting decryption using the tool, as there’s always the possibility of something going wrong and corrupting those files beyond recovery.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:17 pm, Feb. 8, 2025
Wetter-Symbol 5°C
L: 4° | H: 6°
overcast clouds
Luftfeuchtigkeit: 92 %
Druck: 1018 mb
Wind: 10 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 2 km
Sonnenaufgang: 7:27 am
Sonnenuntergang: 5:02 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
4° | 6°°C 0 mm 0% 4 mph 92 % 1023 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 5°°C 1 mm 100% 10 mph 97 % 1030 mb 0 mm/h
Mo. Feb. 10 9:00 pm
Wetter-Symbol
3° | 4°°C 1 mm 100% 11 mph 96 % 1029 mb 1.38 mm/h
Di. Feb. 11 9:00 pm
Wetter-Symbol
3° | 4°°C 0.38 mm 38% 8 mph 97 % 1020 mb 0 mm/h
Mi. Feb. 12 9:00 pm
Wetter-Symbol
4° | 6°°C 0 mm 0% 5 mph 92 % 1023 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 4 mph 92 % 1018 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 86 % 1019 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 81 % 1023 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 84 % 1024 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 87 % 1025 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
4° | 4°°C 0.29 mm 29% 7 mph 94 % 1026 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
4° | 4°°C 0.99 mm 99% 7 mph 97 % 1028 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
4° | 4°°C 1 mm 100% 10 mph 96 % 1028 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,081.62
-1.54%
Ethereum(ETH)
€2,530.67
-5.09%
Fesseln(USDT)
€0.97
-0.04%
XRP(XRP)
€2.33
0.06%
Solana(SOL)
€187.79
-1.97%
USDC(USDC)
€0.97
0.01%
Dogecoin(DOGE)
€0.240031
-2.47%
Shiba Inu(SHIB)
€0.000015
2.96%
Pepe(PEPE)
€0.000009
-3.03%
Nach oben scrollen