Avast Decryption Tool for Fonix helps to unlock data held by the Fonix strain of ransomware.
The Fonix ransomware was active from June 2020. It was written in C++; it uses a three key encryption scheme; RSA-4096 master key, RSA-2048 session key, 256-bit file key for SALSA/ChaCha encryption.
As of February 2021, the ransomware authors shut down their operations and published the master RSA key. This can be used for decrypting files for free. However, it is always advisable to use a trusted source and not anything provided by the cybercriminals for obvious reasons.
The ransomware adds the following extensions:
After Fonix has encrypted files on your machine, the ransomware displays the screen below: