http://7ih75wu7assqw3ros5vhqh4r7folmmliul7yfm5u2vqhlqvf6osn7dyd.onion/archives/2026/05/conti-ransomware-malware-samples-vulnerable-to-cwe-flaws-and-hardcoded-decryption-keys-an-analysis.html
The most important technical finding is that
the documented .lckd encryption implementation is cryptographically
weak. It uses a hard-coded 32-bit XOR key, 0xDEADBEEF, combined with a
bitwise NOT operation over 4-byte chunks. This makes decryption trivial
for any analyst, incident responder, or defender with access to an
encrypted .lckd file.