Researchers at Profero have cracked the encryption used in DarkBit ransomware, enabling free file recovery for victims. The attack was linked to the Iran-nexus threat group MuddyWater APT, which targeted Israeli institutions in 2023. #DarkBit #MuddyWater #VmwareESXi
Keypoints
- Profero developed a method to decrypt DarkBit ransomware files without paying the ransom.
- The DarkBit attack targeted VMware ESXi servers and was suspected to be retaliation for Iranian drone strikes.
- DarkBit ransomware used weak AES-128-CBC encryption that helped researchers brute-force the keys.
- Researchers exploited the partial encryption and sparsity of VMDK files to recover most data without full decryption.
- The case links the DarkBit operation to Iran-based MuddyWater threat actors involved in targeting Israeli institutions.