Recovering files encrypted by Black Basta
Summary
Tobias Mueller analyses the Black Basta encryptor and uses a faulty reuse of the keystream to recover files with a known-plaintext attack. Ransomware can undermine strong primitives itself through faulty use. Data recovery benefits from knowledge of file formats, reverse engineering and cryptography together.
Ideas
- The encryptor reused its keystream in a cryptographically insecure way.
- Known plaintext areas provide information for reconstructing other parts of a file.
- File formats and available original fragments provide usable plaintext assumptions.
- Published tools automate recovery without the extortionists’ key.
Recommendations
- Work only on copies of encrypted drives.
- Keep encrypted files even if no tool is available at first.
References
Links to the original source and the Web Archive open in a new tab.