Regarding Sicarii’s broken decryption process, researchers said that “during execution, the malware regenerates a new RSA key pair locally, uses the newly generated key material for encryption, and then discards the private key.”

  • Natanael@infosec.pub
    link
    fedilink
    arrow-up
    11
    ·
    12 hours ago

    Well, unless they also made key generation shitty, because that’s equally plausible and would likely allow RSA keys to be broken (it’s surprisingly hard to generate RSA keys safely)