Regarding Sicarii’s broken decryption process, researchers said that “during execution, the malware regenerates a new RSA key pair locally, uses the newly generated key material for encryption, and then discards the private key.”

  • Jayjader@jlai.lu
    link
    fedilink
    arrow-up
    0
    ·
    11 hours ago

    ehehehehe thanks for that mental image

    Of course, one can always reclaim that space if the data truly is inaccessible. Makes me want to write a joke program for “cleaning up” after ransomware that just removes the data from the partition table (or whatever the equivalent for files is - would that just be rm?)