Malware News CrypMIC ransomware is a CryptXXX copycat, with a few twists

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
CryptXXX ransomware has a doppelganger.

It's called CrypMIC. And its close resemblance to CryptXXX, the ransomware that's been taking the world by storm since April 2016, doesn't appear to be a coincidence. According to Trend Micro, whose researchers found the malicious code, the most likely scenario is that its makers are looking to cash in on the success of CryptXXX by copying many of its most appealing features.

"On the face of it, this would seem to indicate it's a separate group that is building off of CryptXXX and improving on it,” said Christopher Budd, Trend Micro's global threats communications manager, in an email interview with SCMagazine.com. But CrypMIC is no poser – it has a few original tricks up its own sleeve too.

First, their commonalities: CryptXXX and CrypMIC both spread through compromised websites and malvertising sites via the Neutrino Exploit Kit. Trend Micro said it found Neutrino interchangeably alternating distribution of the two malwares between July 6 and 14.

The two malwares also do more than just encrypt files – they can steal data and credentials from a series of programs. And they present similar content in their ransom notes and payment-site user interfaces.

CrypMIC and CryptXXX can both also encrypt files on removable and network drives, although the former can only encrypt network shares if they have already been mapped to a drive, the blog post explains.

Despite these similarities, CrypMIC and CryptXXX have different source codes – and upon closer inspection, other differences also begin to emerge. Trend Micro notes that unlike its predecessor, CrypMIC does not add an extension name to encrypted files, “making it trickier to determine which files have been held in ransom.”

CrypMIC also stands apart in that it checks for virtual machine environments and sends that information to its command-and-control server. And it uses AES-256 encryption instead of a combination of RSA and RC4, like CRyptXXX.


Read more: CrypMIC ransomware is a CryptXXX copycat, with a few twists

Related article: CrypMIC Ransomware Wants to Follow CryptXXX’s Footsteps - TrendLabs Security Intelligence Blog
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
doppelganger's for sure, but it also looks like they are building off of already existing ransomeware platforms.
Could be form lack of skills or resources so maybe the knock off's will be short lived.
Thanks Jack :)
 
  • Like
Reactions: Logethica

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top