Blog | G5 Cyber Security

EternalPetya and the lost Salsa20 key

The latest Petya seems to be broken on purpose: the victims’ keys are lost forever. A small bug in the Salsa20 implementation has been found, but it is not significant enough to help restoring the key. Once the data is encrypted, having the valid key is the only way to restore it. The new logic implemented in the high-level part (the Windows executable) caused the change in the malwares mission. However, it may be treated as a message about the real intentions of the attackers.”]

Source: https://blog.malwarebytes.com/threat-analysis/2017/06/eternalpetya-lost-salsa20-key/

Exit mobile version