I did some research and the password seem to be required to decrypt the wallet.aes.json file. But maybe it can be worth paying a hacker for that? I would like to know if it's at least possible to recover the funds one way or another.
Theoretically, yes... it can be brute-forced... but that comes with some big caveats...
- You need a good idea of the password length
- You need a good idea of the "structure" of the password (ie. word+word+2digits, or 6 characters+4 digits etc)
- You need to know what characters were used in the password (ie. lowercase, UPPERCASE, numb3r5, Speci@! Symbols etc)
If you know these things... and the password isn't too long (like < 12 chars)... then there is a very good chance it could be bruteforced. There are all manner of scripts available to achieve this... or you could try:
https://www.walletrecoveryservices.com/They have a good reputation and have helped a number of users over the years recovery their wallet passwords etc.