3 ms·
So, to check if I understood. The generated key is encrypted and the user has access to it. So, you send the encrypted key and pay the randsome to get the unec
by pmoleri 9y ago
So, to check if I understood.
The generated key is encrypted and the user has access to it.
So, you send the encrypted key and pay the randsome to get the unecrypted private key. Is that so?
- e12e 9y agoAlmost, the last bit should read: >... get The unencrypted secret symmetric (session/encryption) key So ransomware ships with public key PubK, generates symmetric key K, encrypts user files - plaintext message M to get encrypted files, cipher text C: K=128 random bits, generated on target system C=aes(K, M) Then the key K is encrypted with the public key PubK, yielding encrypted key, Ks. Finally K is deleted from memory/overwritten. Ks can be decrypted by private key PrivK - known only to the author of the ransomware. Now, the victim sends Ks and payment to the author/attacker. The attacker decrypts Ks using PrivK, and gets K, which is sent back to the victim - who can presumably supply K to the ransomware. Ransomware then uses K to decrypt C, yielding M - the unencrypted files.