Guide | How To Destructive malware "CryptoLocker" on the loose - here's what to do

The associated guide may contain user-generated or external content.

nishaddesilva

Level 3
Thread author
Aug 26, 2012
262
SophosLabs has asked us to remind you about a destructive malware threat that calls itself CryptoLocker.

Sophos Anti-Virus detects it by the name Troj/Ransom-ACP, because that's exactly what it does: holds your files to ransom.

Demanding money with menaces

Malware that encrypts your data and tries to sell it back to you, or else, is not new.

In fact, one of the earliest pieces of malware that was written specifically to make money, rather than simply to prove a point, was the AIDS Information Trojan of 1989.

That Trojan scrambled your hard disk after 90 days, and instructed you to send $378 to an accommodation address in Panama.

The perpetrator, one Dr Joseph Popp, was tracked down in the USA, extradited to the UK to stand trial, displayed increasingly shambolic behaviour, and was ultimately kicked out of Britain and never convicted.

Fortunately, his malware was similarly shambolic: it used simplistic encryption algorithms, and every computer was scrambled in the same way, so free tools for cleanup and recovery soon became available.

Sadly, the crooks behind the CryptoLocker malware haven't made the same coding mistakes.

The malware seems to do its cryptography by the book, so there is no way to recover your scrambled files once it has triggered. (You could, I suppose, try paying the ransom, but I recommend that you do not.)

th-170.png


Read more: http://nakedsecurity.sophos.com/2013/10/12/destructive-malware-cryptolocker-on-the-loose/
 

Malware1

Level 76
Sep 28, 2011
6,545
Already posted:

http://malwaretips.com/Thread-The-Future-of-Malware-is-here-%E2%80%93-CryptoLocker
http://malwaretips.com/Thread-CryptoLocker-The-Scariest-Virus-I-seen
 
F

ForgottenSeer 13700

Moose said:
Interesting! Let us know when a cure is available?

The issue is, the encryption seems to be randomly generated; while the AES key seems to be on the system, that appears to be encrypted via another RSA-2048 key, which according to Moore's Law will take 1000's of years to crack.

Prevention is the key here, not a cure.
 

Jack

Administrator
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Moose said:
Interesting! Let us know when a cure is available?
The only solution would be to restore your files from a back-up as the second decryption key is on a the cyber criminals private server.
I have to admit that the guys who created this malware have a lot of guts, as this will more likely upset a lot of people, and without a doubt the law enforcement agencies will try to arrest them as soon as possible.
If the distribution of the CryptoLocker infection will increase, I'm quite confident that there will just a matter of weeks before the authors are arrested and jailed.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top