Malware News New Ransomware using DiskCryptor With Custom Ransom Message

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
A new ransomware has been discovered that installs DiskCryptor on the infected computer and reboots your computer. On reboot, victims will be greeted with a custom ransom note that explains that their disk has been encrypted and how to pay the ransom.

DiskCryptor is a encryption program that encrypts the whole disk and then prompts the user to enter a password on reboot. This password prompt occurs before Windows even starts and a user must enter the password to decrypt the drive and start the computer's normal boot process.

Discovered by MalwareHunterTeam, this ransomware is being run manually or called by another script as it requires an argument to be passed to the program, which is used as the password for DiskCryptor. It is also possible that the attackers are hacking into Remote Desktop Services and installing the ransomware manually.

During the installation process, a log file will be created at C:\Users\Public\myLog.txt that shows the current stage of the encryption process.
 

ChemicalB

Level 8
Verified
Sep 14, 2018
360
This ransomware seems to be "home made" and a little creaky, using a third-party tool for encryption, but well... this doesn't mean it is less dangerous.
 
  • Like
Reactions: upnorth

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top