Victim Q&A · Recovery
Which ransomware decryption tools exist, and are downloaded ones safe to use?
Short answer
Yes, but not many. Legitimate free decryptors come from the No More Ransom project, law enforcement agencies and the official channels of vendors such as Emsisoft, Avast, Kaspersky, Bitdefender and 360, and each usually works only for specific versions of a specific family. Programs circulating online as universal or dedicated decryptors are often malware or paid scams. Even with a genuine tool, confirm the family and version match first, and run it only on copies of your files.
Key points
- Trustworthy sources are few: No More Ransom, law enforcement announcements and vendor websites. Never use decryptors from download sites, file-sharing links or chat groups.
- Public tools cover only a handful of families and usually only specific versions, platforms or time periods; a matching extension proves nothing.
- Identify the family and version before looking for a tool; identification sites return candidates, not conclusions.
- Fake decryptors can encrypt files a second time or plant a trojan, and anything that requires buying decryption software is a red flag.
- Run any tool only on copies, validate on a small sample, then process in batches.
- A version mismatch, overwriting originals in place, or malware still running can turn repairable data into unrecoverable data.
In this order
What to do now
Identify the family and version first
Keep the ransom note, record the appended extension, use ID Ransomware, No More Ransom's Crypto Sheriff or our identification tool to get candidate families, then confirm the exact version from samples.
Look for tools only through official channels
Search No More Ransom's tool list, law enforcement sites and vendor sites, and read the tool's documentation in full: supported extensions, versions, time period, platform and prerequisites.
Make copies
Image the encrypted data read-only or copy it to a separate disk, and leave the original untouched. Keep the tool and its output directory on another disk as well.
Make sure the malware is gone
Work in an isolated environment and confirm the encryptor and any persistence are no longer running; otherwise decrypted files may simply be encrypted again.
Test on a small sample
Decrypt a few files of different types, open each one and check the contents, and only then process in batches, always writing output to a new directory.
Keep every original encrypted file
Do not delete a single encrypted original, or the ransom note, until the recovered data has been checked and accepted.
Avoid making it worse
Do not
- Do not download decryption tools from download sites, file-sharing links, chat groups or search ads.
- Do not pay for dedicated decryption software or decryption codes, and never hand remote access to a server to a stranger who claims they can decrypt.
- Do not run any decryptor directly on original disks or files, or let it write results back over the originals.
- Do not use a tool just because the extension matches; different versions or platform builds of the same family can have opposite outcomes.
- Do not run several tools in turn over the same files; each failed attempt may alter them.
- Do not switch off protection to run an unknown program because antivirus flagged it; judge authenticity by where it came from, not by whether it was flagged.
Where do legitimate free decryptors come from?
Trustworthy sources are few. These channels were still reachable as of September 2026:
| Source | Operated by | Good for | Watch out for |
|---|---|---|---|
| No More Ransom (nomoreransom.org) | A public-interest partnership of law enforcement and security vendors | Finding free tools by family; Crypto Sheriff identification from two encrypted files (1 MB each at most) plus ransom note details | Tools come from different organisations; each tool's own documentation defines its scope |
| Law enforcement announcements | For example Japan's National Police Agency and the US FBI | The Phobos / 8Base decryptor; LockBit victim key matching | Download only from the agency's site or No More Ransom, never from forwarded links |
| Emsisoft decryptor page | Emsisoft | Many families, including STOP/Djvu and GlobeImposter | Many tools need a pair of encrypted and original files; Emsisoft warns tools may not work on versions released after the tool |
| Avast decryptor page and Gen Digital blog | Avast (Gen Digital) | Babuk and TargetCompany, plus early Akira, Mallox, Rhysida and others | Version limits vary widely between tools |
| Kaspersky No Ransom (noransom.kaspersky.com) | Kaspersky | RakhniDecryptor and others, covering early Crysis versions, Dharma and more | This is Kaspersky's site and has no connection with this website, SheMo Noransom |
| Bitdefender | Bitdefender | REvil/Sodinokibi, GandCrab and others | Mostly standalone tools for single families |
| Trend Micro Ransomware File Decryptor | Trend Micro | Twenty-odd older families | The installer has not changed since 2017 and is of little use against recent families |
| 360 Decryption Master and 360 ransomware search engine | 360 | Lookup and decryption for families common in China; some Chinese families require manual assessment by 360's anti-ransomware team | Obtain only through 360's own website and official forum |
| Qi-Anxin decryptor page, Tencent PC Manager ransomware page | Qi-Anxin, Tencent | Lookup by extension or family name | Still online, but mostly covering older families |
Identify the family before hunting for a tool. ID Ransomware, run by MalwareHunterTeam, identifies ransomware from an uploaded note or sample and listed 1,186 detectable families when checked in September 2026. Our own online identification tool and extension lookup are another starting point. Identification sites return candidates; the exact version still needs sample analysis.
Which families have public decryptors, and under what conditions?
The table lists only families where we verified a public tool or a law enforcement key-matching channel. The emphasis is on limits, which matter more than whether a tool exists.
| Family | Tool or key source | Scope and limits |
|---|---|---|
| Phobos / 8Base | Japan's National Police Agency, July 2025, also on No More Ransom | Documented for .phobos, .8base, .elbie, .faust, .LIZARD and related extensions; active ransomware must be removed first or files may be re-encrypted; some browsers and antivirus products flagged it at release |
| LockBit 3.0 | February 2024 law enforcement operation; No More Ransom carries the Japanese police's LockBit 3.0 decryption checker; the FBI said it held over 7,000 keys by June 2024 | The checker uses the decryption ID in the ransom note to indicate whether recovery may be possible and does not itself decrypt; if it may be, you follow instructions to contact law enforcement. LockBit 3.0 only; no public method beyond that |
| Mallox | Avast (Gen Digital), October 2024 | Only files encrypted from 2023 to early 2024, with extensions .bitenc, .ma1x0, .mallab, .malox, .mallox, .malloxx and .xollam; the flaw was fixed around March 2024; must run on the computer where encryption happened |
| Akira | Avast, June 2023; researcher Yohanes Nugroho, March 2025 | Avast's tool targets the earliest version and needs an encrypted and original copy of the same file, and Akira changed its encryption afterwards. The GPU brute-force method published in 2025 targets the 2024 Linux/ESXi variant, depends on untouched file timestamps and a lot of compute, and its author notes newer versions it cannot handle |
| Black Basta | SRLabs' Black Basta Buster, December 2023 | Versions from roughly November 2022 to December 2023; earlier builds using the .basta extension are not covered; files under 5,000 bytes cannot be recovered, and files over 1 GB lose their first 5,000 bytes |
| Rhysida | Flaw published by Korean researchers in February 2024; KISA released a tool, and No More Ransom carries Avast's | Only files encrypted by the Windows encryptor; the ESXi and PowerShell versions are not covered |
| Babuk | Avast; in January 2024, with Cisco Talos and Dutch police, Tortilla variant keys were added | Contains the known private keys; derivatives built from the leaked source with their own keys cannot be decrypted without those keys |
| REvil / Sodinokibi | Bitdefender, September 2021 | Only files encrypted before 13 July 2021 |
| Crysis / Dharma | Kaspersky RakhniDecryptor | Lists Crysis versions 2 and 3, Dharma and other early variants only; do not try it on versions it does not list |
| STOP/Djvu | Emsisoft | Only files encrypted with offline keys Emsisoft holds; files encrypted with an online key cannot be decrypted |
| GlobeImposter | Emsisoft, December 2016 | Only the early .crypt variant imitating Globe, and it needs a file pair; newer variants may not work |
| SnowSoul, Wmansvcs | 360 | Not self-service downloads. SnowSoul: some versions only, after manual assessment by 360's anti-ransomware team. Wmansvcs: free technical support through 360's ransomware forum and other official channels |
| BlackCat / ALPHV | FBI, December 2023 | Decryption capability was offered directly to more than 500 victims and never released publicly; any "BlackCat decryptor" circulating online is untrustworthy |
A family missing from this table is not automatically hopeless. But the families most active in China in recent years - Makop, Weaxor, TellYouThePass, BeijingCrypt and others - have no public free decryptor according to the checks recorded on our family pages. For those, time is better spent on backups, snapshots and structural repair than on hunting for decryptors; see can encrypted files be recovered.
What goes wrong with decryptors downloaded from the internet?
- The fake tool is the malware. In 2020 the Zorab ransomware was distributed disguised as a STOP/Djvu decryptor; victims who ran it had their already-encrypted files encrypted a second time. Programs named as decryptors or removal tools can also carry infostealers or remote-access trojans.
- Lookalike download sites. Searching for a decryptor's "official download" does not guarantee the top result is the official site. Counterfeit download sites and disguised installers are one of the main trojan delivery channels of recent years; the Silver Fox trojan relies on them heavily.
- Paid decryption software and guaranteed decryption. Public decryptors are released free of charge. Be highly suspicious of anyone who wants payment before you can download a dedicated decryptor, or before they send a decryption code. A subtler version exists too: a 2019 ProPublica investigation found US data recovery firms that claimed proprietary decryption technology while actually paying the attackers and adding their own fee. The risks of paying are covered in should we pay the ransom.
- Impersonated "official support". If a tool or support agent claims a link to an agency or vendor, verify through that organisation's own website and ignore links sent in chat.
How do you confirm a tool matches your exact variant?
Check every condition in the tool's documentation against your own samples, not just the extension:
- The family matches. The note's filename, text layout, contact details and victim ID format all agree with the family the tool describes. Look-alike names, impersonators and derivatives built from leaked source are common, and extensions alone are the easiest way to get this wrong.
- The version and date match. Many tools cover only versions from a certain period - the Mallox tool stops at early 2024, for instance. Establish when encryption happened and what build the sample is.
- The platform matches. Windows, Linux and ESXi encryptors are often separate implementations; the Rhysida tool supports only the Windows one.
- The prerequisites are met. For tools that need a file pair, find a pre-encryption original of the same file - a mail attachment, an old backup, the same document in cloud storage. For tools that must run on the original computer, do not reinstall the OS first.
- A small sample passes. Decrypt a few files of different types on copies and open each one to check the contents, rather than trusting the absence of an error message.
If any of these cannot be confirmed, stop and have the samples analysed. Our ransomware decryption service establishes family and version first, and runs a public tool on read-only copies only once the match is confirmed.
When does a failed attempt make files permanently unrecoverable?
Most of the time a failed decryptor simply fails. These situations, however, cause irreversible loss:
- Decrypting in place. With the wrong version or key, a tool may write its incorrect output straight back into the file. Once the original ciphertext is overwritten, even the correct key found later cannot restore it.
- Treating a partly encrypted file as fully encrypted. A mismatched tool "decrypts" the intact regions too, turning plaintext into noise and destroying the room for structural repair along with it.
- Malware still running. When the Phobos / 8Base tool was released, No More Ransom warned that the malware must be removed first or files may be encrypted again and again.
- Installing tools and writing output on the original disk. This overwrites remnants of deleted original files. Keep the tool and its output on another disk.
- Rewritten file timestamps. Some recovery methods rely on modification times to narrow the key search - the published method for Akira's Linux/ESXi variant, for example - and careless copying, opening or renaming can rewrite those timestamps and close the route.
- Deleting encrypted originals right after "success". Output that looks fine does not mean every file is complete. Keep all encrypted originals until acceptance is finished.
Avast's decryptors offer an option in the wizard to back up encrypted files, and it should be ticked. Imaging everything and working on copies is still the safer approach.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related questions
- Recovery
Can files encrypted by ransomware be recovered?
Often in part, sometimes almost entirely, but nobody can promise it before seeing samples. Recoverability comes down to four things: the family and version (is there a public decryptor, seized keys or a known flaw), how the files were encrypted (in full, or only partly), which backups, snapshots and other copies survived, and what has been written to the disks since. Where a modern family encrypted files correctly and completely, no copies survive and the remnants have been overwritten, the data may genuinely be gone. Stop all writes and identify the family first.
- First response
My files all have a new extension and won't open - what should I do?
Do not rename or repair anything yet. If files of many types share the same unfamiliar appended extension (often with an ID and an email address), text, HTA or HTML notes have appeared in every folder and the wallpaper has changed, it is almost certainly ransomware. If only one file type fails, USB files turned into shortcuts, or names are garbled but content opens, a file association, USB worm or encoding problem is more likely. Until you know, disconnect the network, keep the machine on, and save a sample plus the note for identification.
- Ransom & cost
Should we pay the ransom after a ransomware attack?
We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.
- Ransom & cost
How much does ransomware decryption cost, and how long does recovery take?
There is no fixed price and no fixed timeline. Cost and duration depend mainly on whether the family and version can be decrypted, how many hosts and how much data are affected, how hard database and virtual machine repair will be, whether work is remote or on site, and whether overnight parallel work is needed. We do not quote over the phone: we assess first, then issue a written quotation covering scope, deliverables and expected timing, and start once both sides confirm. An initial family read usually takes hours; a full recoverability assessment normally takes one to several business days.
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
Related ransomware families
- Free decryptor available
Phobos
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
- Some versions decryptable
LockBit
LockBit is one of the largest ransomware-as-a-service operations in the world. Despite the 2024 law-enforcement takedown it returned as LockBit 5.0, with working Windows, Linux and VMware ESXi payloads, and it remains one of the most frequently seen families in China.
- Some versions decryptable
Mallox
Mallox (also known as TargetCompany) breaks in mainly through brute-forced MS SQL Server credentials, targets database servers specifically, and has a Linux/ESXi variant. Files encrypted between 2023 and early 2024 may be decryptable with Avast's free tool; later builds have no public decryption method.
- Some versions decryptable
Akira
Akira is a ransomware-as-a-service operation that emerged in March 2023, breaking in through VPNs without MFA and edge-device flaws, then encrypting Windows estates and VMware ESXi clusters under double extortion. CISA's November 2025 advisory update calls it an imminent threat to critical infrastructure.
- Some versions decryptable
Black Basta
Black Basta was a Conti-derived RaaS operation that emerged in April 2022 and affected more than 500 organisations, known for QakBot delivery and Microsoft Teams IT-impersonation social engineering. It disbanded in February 2025 after its internal chat logs leaked, though its tradecraft carried over to successors such as Cactus.
- Some versions decryptable
STOP / Djvu
STOP/Djvu is one of the highest-volume ransomware families worldwide, infecting individuals and micro-businesses mainly through software cracks, activators and game cheats. Extensions are typically four random lowercase letters and the note is _readme.txt. Files encrypted with an offline key can be decrypted free with Emsisoft's tool.
Related solutions
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Database Encrypted by Ransomware
When database files are encrypted, every business system that depends on them stops at once. This page explains how we triage an encrypted database, how recoverability is assessed, and when file repair, backup-plus-log restore, or rebuild is the right path.
FAQ
Follow-up questions
Antivirus flags the decryptor as malware. Does that mean it is fake?
Not necessarily. The Japanese police's Phobos / 8Base tool was flagged by some browsers and antivirus products when it was released. What decides authenticity is where you downloaded it: only from nomoreransom.org, a law enforcement agency or the vendor's own site, and check the hash where one is published. Equally, a clean antivirus result does not make a program of unknown origin safe.
Is Kaspersky's No Ransom site connected with you?
No connection at all. noransom.kaspersky.com is a free decryptor site run by Kaspersky. This website belongs to SheMo Noransom, operated by Zhengzhou Shemo Information Technology Co., Ltd., which has no partnership or affiliation with Kaspersky and does not distribute its tools. For Kaspersky's tools, go directly to Kaspersky's website.
The tool reported success but the files still will not open. What now?
Stop. Do not delete the encrypted originals, and do not move on to a different tool over the same files. The usual causes are a version that does not quite match, files that were only partly encrypted, or output re-encrypted by malware that is still running. Keep the original encrypted samples, the tool's name and version, and the output files together for professional analysis.
There is no tool today. Could one appear later?
Possibly, but nobody can predict it. The Phobos / 8Base tool only arrived in July 2025, and LockBit keys were only seized in quantity after the 2024 law enforcement operation. Keep the encrypted files and ransom note intact on offline media, but do not build the recovery plan around waiting for a tool; pursue the other paths in parallel.
Is it safe to upload samples to identification sites?
Identification sites have to receive the files you upload. ID Ransomware, for example, states that unmatched samples may be shared with trusted malware analysts and that email and bitcoin addresses found in uploads may be passed to law enforcement. Upload only samples that contain nothing sensitive, and in classified or highly sensitive environments do not upload to any public platform at all.
Do you use these public tools, and how do you charge?
Yes. When family and version are confirmed to match, a public tool is often the fastest path, and we run it on read-only copies and verify the results. The tools themselves are free and we never sell decryption tools. The initial conversation and first read on the family are free; fees for a full assessment and recovery work are explained and confirmed before anything starts. See how much ransomware recovery costs and how long it takes.
Sources
- No More Ransom — Decryption Tools
- No More Ransom — Crypto Sheriff
- National Police Agency (Japan) — Phobos/8Base Decryption Tool
- BleepingComputer — New Phobos and 8base ransomware decryptor recover files for free (2025-07-18)
- Security Affairs — Authorities released free decryptor for Phobos and 8base ransomware (2025-07-18)
- No More Ransom — Decryption Checker for LockBit 3.0 Ransomware (guide)
- BleepingComputer — FBI recovers 7,000 LockBit keys, urges ransomware victims to reach out (2024-06-05)
- Gen Digital — Decrypted: Mallox ransomware (2024-10-22)
- BleepingComputer — Free Akira ransomware decryptor helps recover your files (2023-06-30)
- Tinyhack — Decrypting encrypted files from Akira ransomware (Linux/ESXi variant 2024) using a bunch of GPUs (2025-03-13)
- BleepingComputer — New Black Basta decryptor exploits ransomware flaw to recover files (2023-12-30)
- BleepingComputer — Free Rhysida ransomware decryptor for Windows exploits RNG flaw (2024-02)
- Cisco Talos — New decryptor for Babuk Tortilla ransomware variant released (2024-01-09)
- Bitdefender — Bitdefender Offers Free Universal Decryptor for REvil/Sodinokibi Ransomware (2021-09)
- Kaspersky — No Ransom: free ransomware file decryption tools
- Emsisoft — STOP Djvu decryption tool
- Emsisoft — GlobeImposter decryption tool
- Trend Micro — Using the Trend Micro Ransomware File Decryptor Tool
- ID Ransomware (MalwareHunterTeam)
- 360 — 2026 年 8 月勒索软件流行态势分析(2026-09-08)
- 360 — 破解成功|国内顶流勒索软件 Wmansvcs 解密分析(2026-04-16)
- 奇安信 — 勒索病毒解密工具
- 腾讯电脑管家 — 勒索病毒专题
- U.S. Department of Justice — Justice Department Disrupts Prolific ALPHV/Blackcat Ransomware Variant (2023-12-19)
- BleepingComputer — Fake ransomware decryptor double-encrypts desperate victims' files (2020-06-06)
- ProPublica — The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers (2019)
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated