Both BleepingComputer's and Bromium's writeups state that it uses AES. Only the malware exec states that it uses RSA.
Have you tested being able to decrypt using the key.dat?
Have you tested being able to decrypt using the key.dat?
BleepingComputer.com