INCIDENT RECOVERY TOOLKIT

Official Decryption Tools Directory

A curated index of free, legitimate ransomware decryptors released by the FBI, Europol, No More Ransom, and verified research labs. Check here before considering any extortion payment.

Key Facts

  • Catalog of official, verified free ransomware decryption utilities provided by law enforcement and CERTs.
  • Never pay an extortion demand before checking whether universal decryption keys are publicly accessible.
  • All listed utilities are hosted by verified initiatives including No More Ransom, FBI IC3, and Bitdefender.
  • Includes guidance on memory dump preservation and shadow copy recovery prior to running decryptors.

CRITICAL RECOVERY ADVISORY

Before running any decryption executable on encrypted systems: (1) create a bit-stream forensic image of encrypted drives, (2) preserve volatile RAM memory, and (3) verify SHA-256 cryptographic hashes against official law enforcement release bulletins. Fake decryptors distributed on search engines frequently deploy secondary wipers.

LockBit 3.0 / LockBit Black

Released 2024
Authority: National Crime Agency (NCA) / FBI Operation Cronos | Portal: Operation Cronos / Europol No More Ransom

Following the infrastructure takedown of LockBit core servers in February 2024, international law enforcement extracted thousands of decryption keys and released a public verification and recovery portal.

Supported Variants: LockBit 3.0 builds with flawed key derivation or recovered private master keys
Official Repository: Access Verified Decryptor →

ALPHV / BlackCat

Released 2023
Authority: Federal Bureau of Investigation (FBI Cyber Division) | Portal: FBI Flash Alert & No More Ransom

FBI covertly gained access to ALPHV backend affiliate panels, collecting private decryption keys and releasing a Python decryption utility that saved over 500 victim enterprises more than $68 million in ransoms.

Supported Variants: Windows, Linux, and VMware ESXi versions of BlackCat ransomware
Official Repository: Access Verified Decryptor →

Hive Ransomware

Released 2023
Authority: FBI & German Federal Criminal Police (BKA) | Portal: Operation Hive Takedown / No More Ransom

Law enforcement penetrated Hive communication networks in July 2022, capturing decryption keys in real time and providing them directly to victims globally for seven months before seizing server infrastructure.

Supported Variants: Hive v1 through v5 (Go and Rust implementations)
Official Repository: Access Verified Decryptor →

Babuk Ransomware

Released 2021
Authority: Avast Threat Labs & CERT-UA | Portal: Avast Security / CERT Ukraine

Following internal developer disagreements, the complete source code of Babuk Locker was leaked on a Russian-speaking hacker forum, enabling security researchers to construct universal decryptors for ECDH/ChaCha20 keys.

Supported Variants: Babuk Locker Windows and VMware ESXi variants
Official Repository: Access Verified Decryptor →

GandCrab (v1, v4, v5.0 through v5.2)

Released 2019
Authority: Bitdefender & Europol & Romanian Police | Portal: Bitdefender Labs / Europol

Bitdefender identified cryptographic weaknesses in GandCrab random number generation and later partnered with law enforcement to liberate over 40,000 victim machines without paying over $50 million in demands.

Supported Variants: GandCrab versions 1, 4, 5.0.1 through 5.2
Official Repository: Access Verified Decryptor →

MegaCortex

Released 2023
Authority: Bitdefender & Swiss Federal Police & Europol | Portal: Bitdefender & Europol

Following the arrest of twelve ransomware affiliates in Ukraine and Switzerland, investigators seized server drives containing thousands of master private keys.

Supported Variants: MegaCortex versions 1, 2, and 3
Official Repository: Access Verified Decryptor →