Home / Series / Chaos Communication Congress / Aired Order / Season 37 / Episode 23

Unlocked! Recovering files taken hostage by ransomware

We present an analysis and recovery method for files encrypted by Black Basta, the "second most used ransomware in Germany". We analysed the behaviour of a ransomware encryptor and found that the malware uses their keystream wrongly, rendering the encryption vulnerable to a known-plaintext attack which allows for recovering affected files. We confirmed the finding by implementing tools for recovering encrypted files.

English
  • Originally Aired December 27, 2023
  • Runtime 40 minutes
  • Production Code 11903
  • Created January 6, 2025 by
    r4m3u5
  • Modified January 6, 2025 by
    r4m3u5