Nikhil Hegde developed this tool.
Weak encryptionThe Nibiru ransomware is a .NET-based malware family. It traverses directories in the local disks, encrypts files with Rijndael-256 and gives them a .Nibiru extension. Rijndael-256 is a secure encryption algorithm. However, Nibiru uses a hard-coded string “Nibiru” to compute the 32-byte key and 16-byte IV values. The decryptor program leverages this weakness to decrypt files encrypted by this variant.
RansomwareNibiru ransomware is a poorly…
[[ This is only the beginning! Please visit the blog for the complete entry ]]
Go to Source
Author: