Feeds

Ransomware Trojan is back and badder than ever

Hextually transmitted pathogen encrypts files

SANS - Survey on application security programs

A ransomware Trojan threat is back – in an even more noxious form – two years after it last appeared.

A new variant of the GpCode ransomware encrypts user files on infected Windows PCs using theAES 256 and RSA 1024 encryption algorithms. The malware only encrypts the start of media or Office files, but that's enough to make any data recovery process difficult if not impossible.

The latest version of the malware overwrites data in files instead of simply deleting files after encryption, the approach taken by previous versions of GpCode. The approach makes it far harder to use data-recovery software.

The unknown miscreants behind the Trojan – who first started operating in 2004 but have been quiet since 2008 – then demand $120 for keys needed to decrypt files, via a notice displayed on infected machines after the malware has scrambled user files. Other ransomware scams have cropped up over the last two years, but none of these involved variants of the GpCode Trojan, according to net security firm Kaspersky Lab.

A write-up of the attack, together with screenshots, can be found in a blog post by anti-virus analyst Vitaly Kamluk of Kaspersky Lab here. Victims are instructed to send funds via a wire transfer if they ever want to see their data again.

Sophos adds that the malware apparently comes via a drive-by vulnerability from compromised websites, A malicious PDF is reportedly used to download and install the ransomware, which only affects Windows PCs.

Users are advised to regularly back up sensitive data and to use security software as a precaution against possible attacks. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.