Preprint · 22 Aug 2026
Time as a Key: Breaking Rhysida Ransomware with the Attacker’s Own Ciphertext
Download the PDF15 pages · 441 KB · signed by the author. Also on the blog, as a walkthrough.
Verify this copy
The file above carries a PDF certification signature and an RFC 3161 timestamp, so any change made to it after publication is detectable and the date it was signed does not rest on my word alone. The digest and the fingerprint are published here on purpose: read them from this page, not from whoever handed you the file.
- SHA-256
f7dd45169d9b4e9b2475914443a3eccf9ee522f010b92bf74ff871484c14d697 - Signing certificate
D3:13:9F:67:0E:46:10:FD:1F:45:B2:FA:10:42:3E:53:82:D7:D0:FA:F0:67:09:F6:42:F6:33:4A:EE:0A:F0:52 - Timestamped
2026-08-22 21:48:24 UTCby DigiCert - Public certificate adam-taguirov-signing-cert.pem
Self-signed, so a PDF reader will say “valid signature, signer identity unknown” until the certificate is trusted. The fingerprint above is what settles it.
Cite it.
@misc{taguirov2026timeasakey,
author = {Adam Taguirov},
title = {Time as a Key: Breaking Rhysida Ransomware
with the Attacker's Own Ciphertext},
year = {2026},
month = aug,
howpublished = {Preprint, Sigreturn Labs},
url = {https://sigreturn.com/papers/time-as-a-key/}
}