- Number of Unauthorized Cobalt Strike Copies Plummets 80%
- Is your AirTag battery dying too quickly? There's (likely) a fix for that
- José Manuel Rodríguez Jiménez, el español al frente de la transformación digital de la ciudad de Gresham
- 레노버 태블릿, 국내 안드로이드 시장 외산 브랜드 1위··· 삼성전자 이어 점유율 2위 차지
- MS, 오픈AI 경쟁할 자체 추론 모델 개발 난항··· 기술적 한계 외에도 인재 이탈설 나와
Nibiru ransomware variant decryptor – Cisco Blogs

Nikhil Hegde developed this tool.
Weak encryption
The Nibiru ransomware is a .NET-based malware family. It traverses directories in the local disks, encrypts files with Rijndael-256 and gives them a .Nibiru extension. Rijndael-256 is a secure encryption algorithm. However, Nibiru uses a hard-coded string “Nibiru” to compute the 32-byte key and 16-byte IV values. The decryptor program leverages this weakness to decrypt files encrypted by this variant.
Share: