Bedrock Safeguard — Threat Intelligence
Capability C2 — Total cryptanalysis watch

Decryptability Index

Ransomware family → variant/version → decryptor availability. Verdicts come from Bedrock campaign dossiers and the NoMoreRansom public tool list. Anything unverified is marked Unknown — never guessed. Built 2026-07-31.

5/17
Families with a decryptor (29%)
3
Breakable
1
Maybe
4
Not breakable
9
Unknown
FamilyVerdict by variant DecryptorsVerified
Qilin (Agenda)
AES-256-CTR/ChaCha20 + RSA-4096-OAEP, CSPRNG keygen, per-file keys. Bedrock cryptanalysis ruled out batch-GCD, RNG-defect and token-PRNG breaks across the held corpus. No public decryptor.
No
  • No Golang 'Agenda' (2022) — AES-256 + RSA-2048 wrap, CSPRNG per-file keys
  • No Rust rewrite (2022–23) — ChaCha20 + RSA-2048, intermittent-encryption modes
  • No Qilin.B (2024–present) — AES-256-CTR/ChaCha20 + RSA-4096-OAEP; vendor: 'impossible by design'
None verified2026-07-30 · high confidence
hunt/family-campaign-2026-07/qilin.md
Akira (Akira_v2, Megazord)
Lane-specific. Both historical breaks were entropy bugs, patched within weeks-to-months. 2025-era C++ ESXi incidents with intact logs are recoverable via timestamp-seed search; current Windows/Rust builds are not.
Maybe
  • Breakable Windows pre-mid-2023 — Per-execution ChaCha20 key/nonce reuse; needs a known-plaintext pair
  • Maybe C++ Linux/ESXi 2025-era (intact logs) — Timestamp-derived keying — tinyhack seed-search method
  • No Current Windows / Rust Megazord — Patched; proper CSPRNG keying as of 2026-07-30
Avast Akira Decryptor (Avast)Pre-mid-2023 Windows builds only; dead against current variants
2026-07-30 · medium confidence
hunt/family-campaign-2026-07/akira.md
Chaos
The 2025+ family is not breakable for full recovery without the operator private key (CNG-only keygen, sound X25519 escrow). Partial recovery (~70% of ≥4 MiB files) via the stride bug at default encrypt_step=30. All public 'Chaos decryptors' target the unrelated 2021 builder family.
No
  • Breakable Legacy 2021 builder family — Unrelated predecessor; Truesec/NMR decryptor applies
  • No 2025+ builds A/B — Full recovery: NO. Partial (~70% of large files) via stride bug
Truesec Chaos Decryptor (legacy) (Truesec)2021 builder family ONLY — useless against 2025+ Chaos
2026-07-30 · high confidence
hunt/family-campaign-2026-07/chaos.md
Gunra
Split verdict. The July-2025 Linux ELF variant seeded musl rand() with time(NULL) — a working public PoC decryptor exists. The Windows variant uses a proper CSPRNG; March-2026 Linux rebuilds are unverified either way.
Breakable
  • Breakable Linux Jul-2025 — musl rand() time-seeded ChaCha20 IVs; public PoC decryptor
  • No Windows — Proper CSPRNG; hybrid scheme sound
  • Maybe Linux Mar-2026 rebuilds — Unverified — same group shipped rand()+time() once already
gunra_linux_decrypt (PoC) (78ResearchLab)July-2025 Linux ELF variant; known-plaintext probe + candidate brute-force
2026-07-30 · high confidence
hunt/family-campaign-2026-07/gunra.md
Kawa4096
Stream cipher + CSPRNG + likely per-victim Curve25519 wrap; nothing exploitable published. Confidence capped — no tier-1 key-lifecycle audit exists. Partial encryption destroys headers/indexes rather than helping victims.
No
  • No All observed builds — No documented crypto weakness as of 2026-07-30
None verified2026-07-30 · moderate-high confidence
hunt/family-campaign-2026-07/kawa4096.md
Anubis
Standard ECIES secp256k1 + AEAD hybrid via mainstream Go library; private key never present on the victim machine. Wiper mode is unrecoverable by construction.
No
  • No All observed builds — No documented crypto weakness as of 2026-07-30
None verified2026-07-30 · high confidence
hunt/family-campaign-2026-07/anubis.md
LockBit (LockBit 3.0, LockBit Black)
A police-built LockBit 3.0 decryptor is listed on NoMoreRansom (Japanese Police). Coverage of 2024+ LockBit 4.0/5.0 builds is unverified. Family infrastructure was disrupted in 2024 but builds still circulate.
Breakable
  • Breakable LockBit 3.0 (Black) — Japanese Police decryptor via NoMoreRansom
  • Unknown LockBit 4.0 / 5.0 (2024–25) — No verified decryptor coverage
Lockbit 3.0 Decryptor (Japanese Police)LockBit 3.0 builds
2026-07-31 · medium confidence
https://www.nomoreransom.org/en/decryption-tools.html
BlackBasta (Black Basta)
An SR Labs decryptor for BlackBasta is listed on NoMoreRansom. The group collapsed after the 2025 chat-log leak; residual victims of older builds may benefit.
Breakable
  • Breakable Windows builds (per NMR tool scope) — SR Labs decryptor via NoMoreRansom
BlackBasta Decryptor (SR Labs)Per NMR listing; variant scope not further verified
2026-07-31 · medium confidence
https://www.nomoreransom.org/en/decryption-tools.html
Medusa (MedusaLocker)
Active 2026 group. Not yet assessed against the Bedrock flaw catalog; no NMR-listed decryptor as of 2026-07-31.
UnknownNone verified2026-07-31
https://www.nomoreransom.org/en/decryption-tools.html
Play (PlayCrypt)
Active 2026 group. Not yet assessed against the Bedrock flaw catalog; no NMR-listed decryptor as of 2026-07-31.
UnknownNone verified2026-07-31
https://www.nomoreransom.org/en/decryption-tools.html
DragonForce
Active 2026 group. Not yet assessed against the Bedrock flaw catalog; no NMR-listed decryptor as of 2026-07-31.
UnknownNone verified2026-07-31
https://www.nomoreransom.org/en/decryption-tools.html
Cicada3301
Active 2026 group. Not yet assessed against the Bedrock flaw catalog; no NMR-listed decryptor as of 2026-07-31.
UnknownNone verified2026-07-31
https://www.nomoreransom.org/en/decryption-tools.html
Embargo
Active 2026 group. Not yet assessed against the Bedrock flaw catalog; no NMR-listed decryptor as of 2026-07-31.
UnknownNone verified2026-07-31
https://www.nomoreransom.org/en/decryption-tools.html
Lynx
Active 2026 group. Not yet assessed against the Bedrock flaw catalog; no NMR-listed decryptor as of 2026-07-31.
UnknownNone verified2026-07-31
https://www.nomoreransom.org/en/decryption-tools.html
INC Ransom (INC)
Active 2026 group. Not yet assessed against the Bedrock flaw catalog; no NMR-listed decryptor as of 2026-07-31.
UnknownNone verified2026-07-31
https://www.nomoreransom.org/en/decryption-tools.html
RansomHub
Active 2026 group. Not yet assessed against the Bedrock flaw catalog; no NMR-listed decryptor as of 2026-07-31.
UnknownNone verified2026-07-31
https://www.nomoreransom.org/en/decryption-tools.html
Clop (Cl0p)
Active 2026 group. Not yet assessed against the Bedrock flaw catalog; no NMR-listed decryptor as of 2026-07-31.
UnknownNone verified2026-07-31
https://www.nomoreransom.org/en/decryption-tools.html

Coverage counts a family as covered when at least one verified decryptor exists for any known variant — read the scope line on each link: several tools cover legacy builds only and are useless against current production variants. Verdict sources: Bedrock campaign dossiers (hunt/family-campaign-2026-07, verified 2026-07-30) and the NoMoreRansom decryption-tools list (fetched 2026-07-31). This index is regenerated as dossiers land and the sample_crypto_profile flaw queue confirms breaks.

Bedrock Safeguard — Threat Intelligence