Security researchers said companies claiming to decrypt files locked by Dharma/Crisis ransomware are not defeating the malware’s encryption, which experts described as effectively unbreakable without a flaw or the criminals’ private key. An investigation by Emsisoft and outside researchers challenged Australian firm Fast Data Recovery after it advertised a high chance of recovering Dharma-encrypted files and claimed it could reverse engineer decryption keys, despite specialists including Brett Callow, Michael Gillespie, Bill Siegel, and Fabian Wosar saying no such capability is known to exist.
Separate research by Check Point found that Russian service Dr. Shifro allegedly operated as a broker between victims and ransomware operators, buying decryption keys at a discount and reselling recovery at a markup rather than performing true cryptographic recovery. In a sting operation, Check Point observed the service requesting encrypted samples and then contacting the attacker-side email to negotiate key purchases; the researchers linked the activity to iharauch@gmail.com and identified a likely operator in Moscow, estimating profits of about $1,350 per victim and potentially hundreds of thousands of dollars overall.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Check Point noted that another set of Dharma master decryption keys was released in March 2017, though these also did not apply to the newer variants it analyzed.
Previously released Dharma master decryption keys from November 2016 and March 2017 became available, but Check Point said they did not cover the newer variants examined in its investigation.
Check Point Research said the Dharma ransomware family, also known as Crisis, was first observed in 2016.
Security experts including Michael Gillespie, Bill Siegel, and Fabian Wosar said there was no known way to decrypt Dharma without the attackers' key and suggested such firms were likely acting as ransom-paying middlemen.
Fast Data Recovery told Callow that his files belonged to the Dharma family, claimed a very high chance of recovery and a 100% success rate in Dharma cases, and said it would reverse engineer the decryption key.
Brett Callow of Emsisoft posed as a customer and submitted files he had encrypted himself to Fast Data Recovery to test its claim that it could recover Dharma-encrypted data.
Check Point Research published findings that Dr. Shifro was not decrypting newer Dharma/Crisis infections cryptographically, but was instead contacting ransomware operators, buying keys, and reselling recovery services at a markup.
On October 20, during Check Point's controlled test, the fake ransomware operator inbox received a message from iharauch@gmail.com asking for decryption help for the same files sent to Dr. Shifro, linking the intermediary to the service.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcefeatures.propublica.org
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.