Researchers analyzing LooCipher ransomware found that the malware encrypts files with a single AES-128 key in ECB mode, appends the .lcphr extension, and leaves the original files as 0-byte placeholders. Fortinet reported that brute-forcing the key was not practical, but recovery could be possible if defenders captured the malware’s C2 traffic or extracted the encoded key from the memory of a still-running LooCipher process. The analysis also showed the ransomware sends a victim ID, an encoded AES key, and the victim machine’s IP address to its command-and-control server, and that the key encoding could be reversed because it relied on a position-based obfuscation scheme.
Following that finding, ZLab / CERT-Yoroi published a beta decryption tool for LooCipher victims, citing an active infection campaign and crediting Fortinet’s work on the obfuscation flaw. The tool is designed to decrypt files without administrator privileges, but it only works if the infected system has not been restarted after compromise and requires the user to provide the ransomware process ID, underscoring that recovery depends on access to the still-running malware process rather than a universal offline decryptor.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
CERT-Yoroi / ZLab updated the repository README to document the beta LooCipher decryptor, including usage instructions and limitations. The README also credited Fortinet's analysis of an obfuscation flaw that supported part of the recovery approach.
The GitHub repository was updated with a Python source file, "decryptor.py," for the LooCipher decryption tool. The tool requires the victim to provide the ransomware process ID and does not require administrator privileges.
CERT-Yoroi / ZLab added the beta executable "ZLAB_LooCipher_Decryptor.exe" to its GitHub repository for helping LooCipher victims recover files. The repository states the tool was released quickly because of an ongoing LooCipher infection campaign and works only if the infected system has not been restarted.
FortiGuard Labs published an analysis of LooCipher ransomware's encryption routine, finding that the sample used a single AES-128 ECB key for all files and that recovery might be possible by decoding the key from captured C2 traffic or extracting it from process memory. The analysis also noted the malware appends the .lcphr extension and leaves original files as 0-byte files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.