- 웹사이트 인증서가 6주마다 만료되면?··· 기업 IT를 위한 가이드북
- This $200 Android is the only smartphone at CES that you should care about
- CES 2025: The 15 most impressive products you don't want to miss
- 베스핀글로벌 한국 법인, 2024년 흑자 전환 성공
- I tried smart glasses with built-in hearing aids - and they worked surprisingly well at CES
Nibiru ransomware variant decryptor – Cisco Blogs
Nikhil Hegde developed this tool.
Weak encryption
The Nibiru ransomware is a .NET-based malware family. It traverses directories in the local disks, encrypts files with Rijndael-256 and gives them a .Nibiru extension. Rijndael-256 is a secure encryption algorithm. However, Nibiru uses a hard-coded string “Nibiru” to compute the 32-byte key and 16-byte IV values. The decryptor program leverages this weakness to decrypt files encrypted by this variant.
Share: