Avast Decryption Tool for AES_NI can help decrypt the AES_NI ransomware strain. All the Avast Decryption Tools are available in one zip here.
There are known multiple variants with different file extensions. AES_NI uses AES-256 combined with RSA-2048.
The ransomware adds one of the following extensions to encrypted files:
.aes_ni .aes256 .aes_ni_0day
In each folder with at least one encrypted file, the file "!!! READ THIS - IMPORTANT !!!.txt" can be found. Additionally, the ransomware creates a key file with name similar to: [PC_NAME]#9C43A95AC27D3A131D3E8A95F2163088-Bravo NEW-20175267812-78.key.aes_ni_0day in C:ProgramData folder.
The file â€œ!!! READ THIS - IMPORTANT !!!.txtâ€ contains the following ransom note seen in the screenshot below.