Researchers cracked the encryption used by DarkBit ransomware

Researchers cracked the encryption used by DarkBit ransomware

Researchers at Profero have cracked the encryption used in DarkBit ransomware, enabling free file recovery for victims. The attack was linked to the Iran-nexus threat group MuddyWater APT, which targeted Israeli institutions in 2023. #DarkBit #MuddyWater #VmwareESXi

Keypoints

  • Profero developed a method to decrypt DarkBit ransomware files without paying the ransom.
  • The DarkBit attack targeted VMware ESXi servers and was suspected to be retaliation for Iranian drone strikes.
  • DarkBit ransomware used weak AES-128-CBC encryption that helped researchers brute-force the keys.
  • Researchers exploited the partial encryption and sparsity of VMDK files to recover most data without full decryption.
  • The case links the DarkBit operation to Iran-based MuddyWater threat actors involved in targeting Israeli institutions.

Read More: https://securityaffairs.com/181064/malware/researchers-cracked-the-encryption-used-by-darkbit-ransomware.html