"Mistake in ransomware program leaves decryption key accessible"

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
A malicious software program that encrypts a person’s files until a ransom is paid has a crucial error: it leaves the decryption key on the victim’s computer.:p

Symantec analyzed a program called CryptoDefense, which appeared late last month. It’s one of an extensive family of malware programs that scramble a person’s files until a pricey ransom is paid, a long-running but still profitable scam.
CryptoDefense uses Microsoft’s infrastructure and Windows API to generate the encryption and decryption keys, Symantec wrote on its blog.
Files are encrypted by CryptoDefense using a 2048-bit RSA key. The private key needed to decrypt the content is sent back to the attacker’s server until the ransom is paid.
But CryptoDefense’s developers apparently did not realize that the private key is also stashed on the user’s computer in a file folder with application data.

More
 
I

illumination

Was a good laugh.. Only problem now is, that the developer probably read this and is in the process of redirecting their mistake ;)
 
  • Like
Reactions: Venustus

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top