Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Victim Q&A · Recovery

Which ransomware decryption tools exist, and are downloaded ones safe to use?

Short answer

Yes, but not many. Legitimate free decryptors come from the No More Ransom project, law enforcement agencies and the official channels of vendors such as Emsisoft, Avast, Kaspersky, Bitdefender and 360, and each usually works only for specific versions of a specific family. Programs circulating online as universal or dedicated decryptors are often malware or paid scams. Even with a genuine tool, confirm the family and version match first, and run it only on copies of your files.

Key points

  • Trustworthy sources are few: No More Ransom, law enforcement announcements and vendor websites. Never use decryptors from download sites, file-sharing links or chat groups.
  • Public tools cover only a handful of families and usually only specific versions, platforms or time periods; a matching extension proves nothing.
  • Identify the family and version before looking for a tool; identification sites return candidates, not conclusions.
  • Fake decryptors can encrypt files a second time or plant a trojan, and anything that requires buying decryption software is a red flag.
  • Run any tool only on copies, validate on a small sample, then process in batches.
  • A version mismatch, overwriting originals in place, or malware still running can turn repairable data into unrecoverable data.

In this order

What to do now

  1. Identify the family and version first

    Keep the ransom note, record the appended extension, use ID Ransomware, No More Ransom's Crypto Sheriff or our identification tool to get candidate families, then confirm the exact version from samples.

  2. Look for tools only through official channels

    Search No More Ransom's tool list, law enforcement sites and vendor sites, and read the tool's documentation in full: supported extensions, versions, time period, platform and prerequisites.

  3. Make copies

    Image the encrypted data read-only or copy it to a separate disk, and leave the original untouched. Keep the tool and its output directory on another disk as well.

  4. Make sure the malware is gone

    Work in an isolated environment and confirm the encryptor and any persistence are no longer running; otherwise decrypted files may simply be encrypted again.

  5. Test on a small sample

    Decrypt a few files of different types, open each one and check the contents, and only then process in batches, always writing output to a new directory.

  6. Keep every original encrypted file

    Do not delete a single encrypted original, or the ransom note, until the recovered data has been checked and accepted.

Avoid making it worse

Do not

  • Do not download decryption tools from download sites, file-sharing links, chat groups or search ads.
  • Do not pay for dedicated decryption software or decryption codes, and never hand remote access to a server to a stranger who claims they can decrypt.
  • Do not run any decryptor directly on original disks or files, or let it write results back over the originals.
  • Do not use a tool just because the extension matches; different versions or platform builds of the same family can have opposite outcomes.
  • Do not run several tools in turn over the same files; each failed attempt may alter them.
  • Do not switch off protection to run an unknown program because antivirus flagged it; judge authenticity by where it came from, not by whether it was flagged.

Where do legitimate free decryptors come from?

Trustworthy sources are few. These channels were still reachable as of September 2026:

SourceOperated byGood forWatch out for
No More Ransom (nomoreransom.org)A public-interest partnership of law enforcement and security vendorsFinding free tools by family; Crypto Sheriff identification from two encrypted files (1 MB each at most) plus ransom note detailsTools come from different organisations; each tool's own documentation defines its scope
Law enforcement announcementsFor example Japan's National Police Agency and the US FBIThe Phobos / 8Base decryptor; LockBit victim key matchingDownload only from the agency's site or No More Ransom, never from forwarded links
Emsisoft decryptor pageEmsisoftMany families, including STOP/Djvu and GlobeImposterMany tools need a pair of encrypted and original files; Emsisoft warns tools may not work on versions released after the tool
Avast decryptor page and Gen Digital blogAvast (Gen Digital)Babuk and TargetCompany, plus early Akira, Mallox, Rhysida and othersVersion limits vary widely between tools
Kaspersky No Ransom (noransom.kaspersky.com)KasperskyRakhniDecryptor and others, covering early Crysis versions, Dharma and moreThis is Kaspersky's site and has no connection with this website, SheMo Noransom
BitdefenderBitdefenderREvil/Sodinokibi, GandCrab and othersMostly standalone tools for single families
Trend Micro Ransomware File DecryptorTrend MicroTwenty-odd older familiesThe installer has not changed since 2017 and is of little use against recent families
360 Decryption Master and 360 ransomware search engine360Lookup and decryption for families common in China; some Chinese families require manual assessment by 360's anti-ransomware teamObtain only through 360's own website and official forum
Qi-Anxin decryptor page, Tencent PC Manager ransomware pageQi-Anxin, TencentLookup by extension or family nameStill online, but mostly covering older families

Identify the family before hunting for a tool. ID Ransomware, run by MalwareHunterTeam, identifies ransomware from an uploaded note or sample and listed 1,186 detectable families when checked in September 2026. Our own online identification tool and extension lookup are another starting point. Identification sites return candidates; the exact version still needs sample analysis.

Which families have public decryptors, and under what conditions?

The table lists only families where we verified a public tool or a law enforcement key-matching channel. The emphasis is on limits, which matter more than whether a tool exists.

FamilyTool or key sourceScope and limits
Phobos / 8BaseJapan's National Police Agency, July 2025, also on No More RansomDocumented for .phobos, .8base, .elbie, .faust, .LIZARD and related extensions; active ransomware must be removed first or files may be re-encrypted; some browsers and antivirus products flagged it at release
LockBit 3.0February 2024 law enforcement operation; No More Ransom carries the Japanese police's LockBit 3.0 decryption checker; the FBI said it held over 7,000 keys by June 2024The checker uses the decryption ID in the ransom note to indicate whether recovery may be possible and does not itself decrypt; if it may be, you follow instructions to contact law enforcement. LockBit 3.0 only; no public method beyond that
MalloxAvast (Gen Digital), October 2024Only files encrypted from 2023 to early 2024, with extensions .bitenc, .ma1x0, .mallab, .malox, .mallox, .malloxx and .xollam; the flaw was fixed around March 2024; must run on the computer where encryption happened
AkiraAvast, June 2023; researcher Yohanes Nugroho, March 2025Avast's tool targets the earliest version and needs an encrypted and original copy of the same file, and Akira changed its encryption afterwards. The GPU brute-force method published in 2025 targets the 2024 Linux/ESXi variant, depends on untouched file timestamps and a lot of compute, and its author notes newer versions it cannot handle
Black BastaSRLabs' Black Basta Buster, December 2023Versions from roughly November 2022 to December 2023; earlier builds using the .basta extension are not covered; files under 5,000 bytes cannot be recovered, and files over 1 GB lose their first 5,000 bytes
RhysidaFlaw published by Korean researchers in February 2024; KISA released a tool, and No More Ransom carries Avast'sOnly files encrypted by the Windows encryptor; the ESXi and PowerShell versions are not covered
BabukAvast; in January 2024, with Cisco Talos and Dutch police, Tortilla variant keys were addedContains the known private keys; derivatives built from the leaked source with their own keys cannot be decrypted without those keys
REvil / SodinokibiBitdefender, September 2021Only files encrypted before 13 July 2021
Crysis / DharmaKaspersky RakhniDecryptorLists Crysis versions 2 and 3, Dharma and other early variants only; do not try it on versions it does not list
STOP/DjvuEmsisoftOnly files encrypted with offline keys Emsisoft holds; files encrypted with an online key cannot be decrypted
GlobeImposterEmsisoft, December 2016Only the early .crypt variant imitating Globe, and it needs a file pair; newer variants may not work
SnowSoul, Wmansvcs360Not self-service downloads. SnowSoul: some versions only, after manual assessment by 360's anti-ransomware team. Wmansvcs: free technical support through 360's ransomware forum and other official channels
BlackCat / ALPHVFBI, December 2023Decryption capability was offered directly to more than 500 victims and never released publicly; any "BlackCat decryptor" circulating online is untrustworthy

A family missing from this table is not automatically hopeless. But the families most active in China in recent years - Makop, Weaxor, TellYouThePass, BeijingCrypt and others - have no public free decryptor according to the checks recorded on our family pages. For those, time is better spent on backups, snapshots and structural repair than on hunting for decryptors; see can encrypted files be recovered.

What goes wrong with decryptors downloaded from the internet?

  • The fake tool is the malware. In 2020 the Zorab ransomware was distributed disguised as a STOP/Djvu decryptor; victims who ran it had their already-encrypted files encrypted a second time. Programs named as decryptors or removal tools can also carry infostealers or remote-access trojans.
  • Lookalike download sites. Searching for a decryptor's "official download" does not guarantee the top result is the official site. Counterfeit download sites and disguised installers are one of the main trojan delivery channels of recent years; the Silver Fox trojan relies on them heavily.
  • Paid decryption software and guaranteed decryption. Public decryptors are released free of charge. Be highly suspicious of anyone who wants payment before you can download a dedicated decryptor, or before they send a decryption code. A subtler version exists too: a 2019 ProPublica investigation found US data recovery firms that claimed proprietary decryption technology while actually paying the attackers and adding their own fee. The risks of paying are covered in should we pay the ransom.
  • Impersonated "official support". If a tool or support agent claims a link to an agency or vendor, verify through that organisation's own website and ignore links sent in chat.

How do you confirm a tool matches your exact variant?

Check every condition in the tool's documentation against your own samples, not just the extension:

  1. The family matches. The note's filename, text layout, contact details and victim ID format all agree with the family the tool describes. Look-alike names, impersonators and derivatives built from leaked source are common, and extensions alone are the easiest way to get this wrong.
  2. The version and date match. Many tools cover only versions from a certain period - the Mallox tool stops at early 2024, for instance. Establish when encryption happened and what build the sample is.
  3. The platform matches. Windows, Linux and ESXi encryptors are often separate implementations; the Rhysida tool supports only the Windows one.
  4. The prerequisites are met. For tools that need a file pair, find a pre-encryption original of the same file - a mail attachment, an old backup, the same document in cloud storage. For tools that must run on the original computer, do not reinstall the OS first.
  5. A small sample passes. Decrypt a few files of different types on copies and open each one to check the contents, rather than trusting the absence of an error message.

If any of these cannot be confirmed, stop and have the samples analysed. Our ransomware decryption service establishes family and version first, and runs a public tool on read-only copies only once the match is confirmed.

When does a failed attempt make files permanently unrecoverable?

Most of the time a failed decryptor simply fails. These situations, however, cause irreversible loss:

  • Decrypting in place. With the wrong version or key, a tool may write its incorrect output straight back into the file. Once the original ciphertext is overwritten, even the correct key found later cannot restore it.
  • Treating a partly encrypted file as fully encrypted. A mismatched tool "decrypts" the intact regions too, turning plaintext into noise and destroying the room for structural repair along with it.
  • Malware still running. When the Phobos / 8Base tool was released, No More Ransom warned that the malware must be removed first or files may be encrypted again and again.
  • Installing tools and writing output on the original disk. This overwrites remnants of deleted original files. Keep the tool and its output on another disk.
  • Rewritten file timestamps. Some recovery methods rely on modification times to narrow the key search - the published method for Akira's Linux/ESXi variant, for example - and careless copying, opening or renaming can rewrite those timestamps and close the route.
  • Deleting encrypted originals right after "success". Output that looks fine does not mean every file is complete. Keep all encrypted originals until acceptance is finished.

Avast's decryptors offer an option in the wizard to back up encrypted files, and it should be ticked. Imaging everything and working on copies is still the safer approach.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related questions

Related ransomware families

FAQ

Follow-up questions

  • Antivirus flags the decryptor as malware. Does that mean it is fake?

    Not necessarily. The Japanese police's Phobos / 8Base tool was flagged by some browsers and antivirus products when it was released. What decides authenticity is where you downloaded it: only from nomoreransom.org, a law enforcement agency or the vendor's own site, and check the hash where one is published. Equally, a clean antivirus result does not make a program of unknown origin safe.

  • Is Kaspersky's No Ransom site connected with you?

    No connection at all. noransom.kaspersky.com is a free decryptor site run by Kaspersky. This website belongs to SheMo Noransom, operated by Zhengzhou Shemo Information Technology Co., Ltd., which has no partnership or affiliation with Kaspersky and does not distribute its tools. For Kaspersky's tools, go directly to Kaspersky's website.

  • The tool reported success but the files still will not open. What now?

    Stop. Do not delete the encrypted originals, and do not move on to a different tool over the same files. The usual causes are a version that does not quite match, files that were only partly encrypted, or output re-encrypted by malware that is still running. Keep the original encrypted samples, the tool's name and version, and the output files together for professional analysis.

  • There is no tool today. Could one appear later?

    Possibly, but nobody can predict it. The Phobos / 8Base tool only arrived in July 2025, and LockBit keys were only seized in quantity after the 2024 law enforcement operation. Keep the encrypted files and ransom note intact on offline media, but do not build the recovery plan around waiting for a tool; pursue the other paths in parallel.

  • Is it safe to upload samples to identification sites?

    Identification sites have to receive the files you upload. ID Ransomware, for example, states that unmatched samples may be shared with trusted malware analysts and that email and bitcoin addresses found in uploads may be passed to law enforcement. Upload only samples that contain nothing sensitive, and in classified or highly sensitive environments do not upload to any public platform at all.

  • Do you use these public tools, and how do you charge?

    Yes. When family and version are confirmed to match, a public tool is often the fastest path, and we run it on read-only copies and verify the results. The tools themselves are free and we never sell decryption tools. The initial conversation and first read on the family are free; fees for a full assessment and recovery work are explained and confirmed before anything starts. See how much ransomware recovery costs and how long it takes.

Sources

External links are provided for reference only. The content is published by third parties and does not represent our position.

Updated