I have written about the CryptoLocker virus and other security problems countless times in this blog and here is yet another recent real life example of what can go wrong with computer security, even when police departments are involved.
A U.S. police department was so determined to get back important files that had been encrypted by the rampaging CryptoLocker Trojan it decided to pay the ransom being demanded by the criminals.
It sounds like a far-fetched and probably serious breach of law enforcement protocol, but according to a local news report, this is exactly what the police department in Swansea, Mass., decided to do when "several images and word documents," were found to have been encrypted by the malware.
The department had followed the instructions given by CryptoLocker and on Nov. 10 bought two bitcoins worth $750 which resulted in the criminals sending the decrypt key, police said.
The "Trojan" is so complicated and successful that you have to buy these bitcoins, which we had never heard of," said Swansea Police Lt. Gregory Ryan in an admission to the press many will find quite staggering.
Ryan didn't say why the files were so important that a police department saw fit to pay a digital ransom to criminals, but insisted "It was an education for [those who] had to deal with it," and that at least the infection had not caused damage to the system the department used for booking official reports and logging photographs.
"We were never compromised," Ryan said, a statement that many would deem inaccurate.
Only last weekend, the UK National Crime Agency put out an alert that the criminals behind CryptoLocker were now targeting UK SMEs on a large scale. Their recommendation is that affected businesses do not pay the ransom, not least because there is no guarantee that they will even receive an unlock key.
There is growing concern about the scale and success of the CryptoLocker campaign which, it is worth pointing out, is far from the first malware to use the technique of locking or encrypting victim's files. A key element of CryptoLocker's recent success is that it has started demanding untraceable bitcoins for payment rather than more conventional money channels that were easier to block or trace.
Another weakness is that there is often no central place for affected individuals to report infections, nor seek advice. Consequently, some victims pay up. The citizens of Swansea, Mass., now know that this helplessness includes their local police department.
"With the FBI stating that this type of activity should not be encouraged by paying the ransom, it is surprising to see that the local police department paying to regain access to the files," commented Gavin Millard, EMEA technical director of security firm Tripwire.
"What is more concerning though, is the apparent lack of security and backup procedures on systems that could be storing critical and highly confidential documents."
I have written this countless times on this little tech blog. Never ever open attachments that you did not specifically ask for. When in doubt, contact the sender by phone to verify that the attachment is legitimate. Otherwise you may be in the same sinking boat as the police department in this article.
Showing posts with label crypto-locker. Show all posts
Showing posts with label crypto-locker. Show all posts
Tuesday, November 26, 2013
Friday, November 15, 2013
TA13-309A: CryptoLocker Ransomware Infections
This is the 3rd Cyrpto-Locker Alert issued by the US Government.
Please take it seriously bloggers.
Original release date: November 05, 2013 | Last revised: November 15, 2013
Systems Affected
Microsoft Windows systems running Windows 8, Windows 7, Vista, and XP operating systems
Overview
US-CERT is aware of a malware campaign that surfaced in 2013 and is associated with an increasing number of ransomware infections. CryptoLocker is a new variant of ransomware that restricts access to infected computers and demands the victim provide a payment to the attackers in order to decrypt and recover their files. As of this time, the primary means of infection appears to be phishing emails containing malicious attachments.
Description
CryptoLocker appears to have been spreading through fake emails designed to mimic the look of legitimate businesses and through phony FedEx and UPS tracking notices. In addition, there have been reports that some victims saw the malware appear following after a previous infection from one of several botnets frequently leveraged in the cyber-criminal underground.
Impact
The malware has the ability to find and encrypt files located within shared network drives, USB drives, external hard drives, network file shares and even some cloud storage drives. If one computer on a network becomes infected, mapped network drives could also become infected. CryptoLocker then connects to the attackers’ command and control (C2) server to deposit the asymmetric private encryption key out of the victim’s reach.
Victim files are encrypted using asymmetric encryption. Asymmetric encryption uses two different keys for encrypting and decrypting messages. Asymmetric encryption is a more secure form of encryption as only one party is aware of the private key, while both sides know the public key.
While victims are told they have three days to pay the attacker through a third-party payment method (MoneyPak, Bitcoin), some victims have claimed online that they paid the attackers and did not receive the promised decryption key. US-CERT and DHS encourage users and administrators experiencing a ransomware infection to report the incident to the FBI at the Internet Crime Complaint Center (IC3).
Solution
Prevention
US-CERT recommends users and administrators take the following preventative measures to protect their computer networks from a CryptoLocker infection:
Mitigation
US-CERT suggests the following possible mitigation steps that users and administrators can implement, if you believe your computer has been infected with CryptoLocker malware:
References
Revision History
Please take it seriously bloggers.
Original release date: November 05, 2013 | Last revised: November 15, 2013
Systems Affected
Microsoft Windows systems running Windows 8, Windows 7, Vista, and XP operating systems
Overview
US-CERT is aware of a malware campaign that surfaced in 2013 and is associated with an increasing number of ransomware infections. CryptoLocker is a new variant of ransomware that restricts access to infected computers and demands the victim provide a payment to the attackers in order to decrypt and recover their files. As of this time, the primary means of infection appears to be phishing emails containing malicious attachments.
Description
CryptoLocker appears to have been spreading through fake emails designed to mimic the look of legitimate businesses and through phony FedEx and UPS tracking notices. In addition, there have been reports that some victims saw the malware appear following after a previous infection from one of several botnets frequently leveraged in the cyber-criminal underground.
Impact
The malware has the ability to find and encrypt files located within shared network drives, USB drives, external hard drives, network file shares and even some cloud storage drives. If one computer on a network becomes infected, mapped network drives could also become infected. CryptoLocker then connects to the attackers’ command and control (C2) server to deposit the asymmetric private encryption key out of the victim’s reach.
Victim files are encrypted using asymmetric encryption. Asymmetric encryption uses two different keys for encrypting and decrypting messages. Asymmetric encryption is a more secure form of encryption as only one party is aware of the private key, while both sides know the public key.
While victims are told they have three days to pay the attacker through a third-party payment method (MoneyPak, Bitcoin), some victims have claimed online that they paid the attackers and did not receive the promised decryption key. US-CERT and DHS encourage users and administrators experiencing a ransomware infection to report the incident to the FBI at the Internet Crime Complaint Center (IC3).
Solution
Prevention
US-CERT recommends users and administrators take the following preventative measures to protect their computer networks from a CryptoLocker infection:
- Do not follow unsolicited web links in email messages
or submit any information to webpages in links
- Use caution when opening email attachments. Refer to
the Security Tip Using
Caution with Email Attachments for more information on safely handling
email attachments
- Maintain up-to-date anti-virus software
- Perform regular offline backups of all systems to limit
the impact of data and/or system loss
- Apply changes to your Intrusion Detection/Prevention
Systems and Firewalls to detect any known malicious activity
- Secure open-share drives by only allowing writable
access to necessary user groups or authenticated users
- Keep your operating system and software up-to-date with
the latest patches
- Refer to the Recognizing
and Avoiding Email Scams (pdf) document for more information on
avoiding email scams
- Refer to the Security Tip Avoiding Social
Engineering and Phishing Attacks for more information on social
engineering attacks
Mitigation
US-CERT suggests the following possible mitigation steps that users and administrators can implement, if you believe your computer has been infected with CryptoLocker malware:
- Immediately disconnect the infected system from the
wireless or wired network. This may prevent the malware from further
encrypting any more files on the network
- Users who are infected should change all passwords
AFTER removing the malware from their system
- Users who are infected with the malware should consult
with a reputable security expert to assist in removing the malware, or
users can retrieve encrypted files by the following methods:
- Restore from backup,
- Restore from a shadow
copy or
- Perform a system
restore.
References
- CryptoLocker
Virus: New Malware Holds Computers For Ransom, Demands $300 Within 100
Hours And Threatens To Encrypt Hard Drive
- CryptoLocker
Wants Your Money!
- CryptoLocker
ransomware – see how it works, learn about prevention, cleanup and
recovery
- Microsoft
Support – Description of the Software Restriction Policies in Windows XP
- Microsoft
Software Restriction Policies Technical Reference – How Software
Restriction Policies Work
- CryptoLocker
Ransomware Information Guide and FAQ
Revision History
- November 5, 2013: Initial Release
- November 13, 2013: Update to Systems Affected
(inclusion of Windows 8)
- November 15, 2013: Updates to Impact and Prevention
sections.
Wednesday, November 6, 2013
TA13-309A: CryptoLocker Ransomware Infections
As I have reported previously the CryptoLocker virus is a very serious computer threat to everyone.
The United States Emergency Computer Response Team (US-CERT) has today issued an alert regarding the threat. I have been posting relevant US-CERT warnings on this blog so here is this one.
The United States Emergency Computer Response Team (US-CERT) has today issued an alert regarding the threat. I have been posting relevant US-CERT warnings on this blog so here is this one.
Systems Affected
Microsoft Windows systems running Windows 7, Vista, and XP operating systems
Overview
US-CERT is aware of a malware campaign that surfaced in 2013 and is associated with an increasing number of ransomware infections. CryptoLocker is a new variant of ransomware that restricts access to infected computers and demands the victim provide a payment to the attackers in order to decrypt and recover their files. As of this time, the primary means of infection appears to be phishing emails containing malicious attachments.
Description
CryptoLocker appears to have been spreading through fake emails designed to mimic the look of legitimate businesses and through phony FedEx and UPS tracking notices. In addition, there have been reports that some victims saw the malware appear following after a previous infection from one of several botnets frequently leveraged in the cyber-criminal underground.
Impact
The malware has the ability to find and encrypt files located within shared network drives, USB drives, external hard drives, network file shares and even some cloud storage drives. If one computer on a network becomes infected, mapped network drives could also become infected. CryptoLocker then connects to the attackers’ command and control (C2) server to deposit the asymmetric private encryption key out of the victim’s reach.
Victim files are encrypted using asymmetric encryption. Asymmetric encryption uses two different keys for encrypting and decrypting messages. Asymmetric encryption is a more secure form of encryption as only one party is aware of the private key, while both sides know the public key.
While victims are told they have three days to pay the attacker through a third-party payment method (MoneyPak, Bitcoin), some victims have claimed online that they paid the attackers and did not receive the promised decryption key. US-CERT and DHS encourage users and administrators experiencing a ransomware infection NOT to respond to extortion attempts by attempting payment and instead to report the incident to the FBI at the Internet Crime Complaint Center (IC3).
Victim files are encrypted using asymmetric encryption. Asymmetric encryption uses two different keys for encrypting and decrypting messages. Asymmetric encryption is a more secure form of encryption as only one party is aware of the private key, while both sides know the public key.
While victims are told they have three days to pay the attacker through a third-party payment method (MoneyPak, Bitcoin), some victims have claimed online that they paid the attackers and did not receive the promised decryption key. US-CERT and DHS encourage users and administrators experiencing a ransomware infection NOT to respond to extortion attempts by attempting payment and instead to report the incident to the FBI at the Internet Crime Complaint Center (IC3).
Solution
Prevention
US-CERT recommends users and administrators take the following preventative measures to protect their computer networks from a CryptoLocker infection:
US-CERT suggests the following possible mitigation steps that users and administrators can implement, if you believe your computer has been infected with CryptoLocker malware:
US-CERT recommends users and administrators take the following preventative measures to protect their computer networks from a CryptoLocker infection:
- Do not follow unsolicited web links in email messages or submit any information to webpages in links
- Use caution when opening email attachments. Refer to the Security Tip Using Caution with Email Attachments for more information on safely handling email attachments
- Maintain up-to-date anti-virus software
- Perform regular backups of all systems to limit the impact of data and/or system loss
- Apply changes to your Intrusion Detection/Prevention Systems and Firewalls to detect any known malicious activity
- Secure open-share drives by only allowing connections from authorized users
- Keep your operating system and software up-to-date with the latest patches
- Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams
- Refer to the Security Tip Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks
US-CERT suggests the following possible mitigation steps that users and administrators can implement, if you believe your computer has been infected with CryptoLocker malware:
- Immediately disconnect the infected system from the wireless or wired network. This may prevent the malware from further encrypting any more files on the network
- Users who are infected should change all passwords AFTER removing the malware from their system
- Users who are infected with the malware should consult with a reputable security expert to assist in removing the malware, or users can retrieve encrypted files by the following methods:
- Restore from backup,
- Restore from a shadow copy or
- Perform a system restore.
References
- CryptoLocker Virus: New Malware Holds Computers For Ransom, Demands $300 Within 100 Hours And Threatens To Encrypt Hard Drive
- CryptoLocker Wants Your Money!
- CryptoLocker ransomware – see how it works, learn about prevention, cleanup and recovery
- Microsoft Support – Description of the Software Restriction Policies in Windows XP
- Microsoft Software Restriction Policies Technical Reference – How Software Restriction Policies Work
- CryptoLocker Ransomware Information Guide and FAQ
Tuesday, November 5, 2013
CryptoLocker Threat Worsens
Last week I reported about a new serious security issue known as "CryptoLocker" which is a real threat to an infected user's data. PC World recently re-visited this malware threat and I posted it here because it is so important to avoid.
Before I continue with PC World's article I must suggest again, "never ever open an attachment unless you specifically requested the file". This is the only way to avoid this and other security threats.
The creators of CryptoLocker, a piece of malware that encrypts user data and holds it for ransom, are giving users who removed the malicious program from their computers a second chance to recover their files, but at a much higher cost.
CryptoLocker is a malicious program that falls into a category of malware called ransomware. Once installed on a computer, ransomware applications typically prevent victims from accessing their files or even their operating system until they pay money to the malware authors.
Security researchers generally advise users against giving into this kind of extortion and in many cases there is a way to regain access to everything without paying up.
However, CryptoLocker uses solid public-private key cryptography to encrypt files that match a long list of extensions, including documents, spreadsheets, images and even AutoCAD design files. According to researchers from antivirus firm Sophos, the malware’s creators got the encryption process right and there’s no method to get the decryption keys, which are unique for every computer and are stored on attackers’ servers, without paying up.
After it infects a computer, CryptoLocker displays a message informing victims that if they don’t pay the equivalent of $300 or €300 in Bitcoins, a virtual currency, or via MoneyPak, a type of prepaid card, within 72 hours, the unique decryption key for the files will be automatically destroyed.
Users who regularly back up their data can clean their computers and restore the affected files from backups, but users who don’t have backups should consider those files lost, the Sophos researchers said.
Some files might be recoverable using the Shadow Copy technology, which is is an integral part of the System Restore feature in Windows.
However, even users who have backups might realize that they’re not enough to repair the damage done by the malware. Those backups might be too old or they might not include files from remote network shares that have also been encrypted by the malware.
It seems that the creators of CryptoLocker considered that possibility and realized that some users might have initially removed the malware, but then, for whatever reason, changed their mind about paying up. As a result, they’ve recently started offering an online decryption service that allow such users to still recover their files, but at a much higher price.
“Apparently the crooks will now let you buy back your key even if you didn’t follow their original instructions,” Paul Ducklin, the head of technology for the Asia-Pacific region at Sophos, said last Monday. “Word on the street, however, is that the crooks want five times as much as they were charging originally to decrypt your data after you change your mind.”
The cost of using the service is 10 Bitcoins—around $2300 at the current Bitcoin exchange rate—and requires users to upload one of their encrypted files. The first 1024 bytes of the file will be used to search for the associated private key, a process that can take up to 24 hours.
“We’re guessing that the delay is because the crooks have to run a brute force attack against themselves,” Ducklin said. “Without your public key to help them match up your keypair in their database, it sounds as though they have to try to decrypting your data with every stored private key until they hit one that produces a plausible result.”
However it’s not immediately clear whether using this service is still possible after the initial 72-hour deadline given by the malware. If it is, then the cybercriminals lied and the private keys are not being destroyed after that time period.
This decryption service might have also been created for users whose antivirus programs detected and deleted the malware after it encrypted the files, leaving them unable to buy the decryption key anymore.
“We’re still saying, ‘don’t buy,’ but we’re feeling your pain enough to know how tempting it will be for some people to pay the crooks, even though the blackmail charges have now ballooned to more than $2000,” Ducklin said.
Before I continue with PC World's article I must suggest again, "never ever open an attachment unless you specifically requested the file". This is the only way to avoid this and other security threats.
The creators of CryptoLocker, a piece of malware that encrypts user data and holds it for ransom, are giving users who removed the malicious program from their computers a second chance to recover their files, but at a much higher cost.
CryptoLocker is a malicious program that falls into a category of malware called ransomware. Once installed on a computer, ransomware applications typically prevent victims from accessing their files or even their operating system until they pay money to the malware authors.
Security researchers generally advise users against giving into this kind of extortion and in many cases there is a way to regain access to everything without paying up.
However, CryptoLocker uses solid public-private key cryptography to encrypt files that match a long list of extensions, including documents, spreadsheets, images and even AutoCAD design files. According to researchers from antivirus firm Sophos, the malware’s creators got the encryption process right and there’s no method to get the decryption keys, which are unique for every computer and are stored on attackers’ servers, without paying up.
After it infects a computer, CryptoLocker displays a message informing victims that if they don’t pay the equivalent of $300 or €300 in Bitcoins, a virtual currency, or via MoneyPak, a type of prepaid card, within 72 hours, the unique decryption key for the files will be automatically destroyed.
Users who regularly back up their data can clean their computers and restore the affected files from backups, but users who don’t have backups should consider those files lost, the Sophos researchers said.
Some files might be recoverable using the Shadow Copy technology, which is is an integral part of the System Restore feature in Windows.
However, even users who have backups might realize that they’re not enough to repair the damage done by the malware. Those backups might be too old or they might not include files from remote network shares that have also been encrypted by the malware.
It seems that the creators of CryptoLocker considered that possibility and realized that some users might have initially removed the malware, but then, for whatever reason, changed their mind about paying up. As a result, they’ve recently started offering an online decryption service that allow such users to still recover their files, but at a much higher price.
“Apparently the crooks will now let you buy back your key even if you didn’t follow their original instructions,” Paul Ducklin, the head of technology for the Asia-Pacific region at Sophos, said last Monday. “Word on the street, however, is that the crooks want five times as much as they were charging originally to decrypt your data after you change your mind.”
The cost of using the service is 10 Bitcoins—around $2300 at the current Bitcoin exchange rate—and requires users to upload one of their encrypted files. The first 1024 bytes of the file will be used to search for the associated private key, a process that can take up to 24 hours.
“We’re guessing that the delay is because the crooks have to run a brute force attack against themselves,” Ducklin said. “Without your public key to help them match up your keypair in their database, it sounds as though they have to try to decrypting your data with every stored private key until they hit one that produces a plausible result.”
However it’s not immediately clear whether using this service is still possible after the initial 72-hour deadline given by the malware. If it is, then the cybercriminals lied and the private keys are not being destroyed after that time period.
This decryption service might have also been created for users whose antivirus programs detected and deleted the malware after it encrypted the files, leaving them unable to buy the decryption key anymore.
“We’re still saying, ‘don’t buy,’ but we’re feeling your pain enough to know how tempting it will be for some people to pay the crooks, even though the blackmail charges have now ballooned to more than $2000,” Ducklin said.
Wednesday, October 30, 2013
Crypto Locker Warning
It seems like I write monthly about computer security but if you needed a reminder to be careful about the emails and attachments you open, it’s now. The Crypto Locker virus that is going around is said to be one of the worst ever and is infecting computers with the Windows OS all across the United States. The virus, also called “ransomware,” works by holding your files hostage until you pay a fee.
The Crypto Locker virus is passed around in emails that have innocent enough looking senders, such as UPS or FedEx, but they’re not really from these corporations, of course. Instead, when you open the attachment, your computer becomes infected and the virus locks all your files until you pay a ransom. Check out a picture of what the Crypto Locker demand screen looks like:
Ransomware causes your computer files to be non-accessible and when that happens you have two choices. You can recover if you have a backup which I hope you do or pay the ransom within 100 hours. If you do not pay the ransom you will lose all of your data.
The Crypto Locker email pretends often pretends to be from a financial institution like a bank or Pay Pal and reports that it has dire news for you and that the attachment is important. readers of these emails often panic and open the attachment and then it's too late. The PC is infected and the files are encrypted which means you cannot open your own files. The attachment will often disguise itself as JPEG images, as PDF files, as Microsoft Office files and many other file types. After the computer becomes infected, users are usually given 100 hours to pay a fee between $100 and $700 to get the files decrypted.
This Is Important - Follow These Rules
1. If you get an email from somebody you do not know, especially if it has attachments, do not open anything with it, just delete the email.
2. If you did not specifically ask for an attachment do not open it. If you are curious reach out to the send by phone before opening anything. If you cannot contact the send do not open it!
Backing Up Your Files is More Important Then Ever
Make sure you have all of your files backed up both on a local disconnected USB hard drive and in the cloud. There are many free and affordable cloud services available so there is really no excuse not to do this. If your PC gets infected with the Crypto Locker virus you backup may be your digital salvation.
The Crypto Locker virus is passed around in emails that have innocent enough looking senders, such as UPS or FedEx, but they’re not really from these corporations, of course. Instead, when you open the attachment, your computer becomes infected and the virus locks all your files until you pay a ransom. Check out a picture of what the Crypto Locker demand screen looks like:
Ransomware causes your computer files to be non-accessible and when that happens you have two choices. You can recover if you have a backup which I hope you do or pay the ransom within 100 hours. If you do not pay the ransom you will lose all of your data.
The Crypto Locker email pretends often pretends to be from a financial institution like a bank or Pay Pal and reports that it has dire news for you and that the attachment is important. readers of these emails often panic and open the attachment and then it's too late. The PC is infected and the files are encrypted which means you cannot open your own files. The attachment will often disguise itself as JPEG images, as PDF files, as Microsoft Office files and many other file types. After the computer becomes infected, users are usually given 100 hours to pay a fee between $100 and $700 to get the files decrypted.
This Is Important - Follow These Rules
1. If you get an email from somebody you do not know, especially if it has attachments, do not open anything with it, just delete the email.
2. If you did not specifically ask for an attachment do not open it. If you are curious reach out to the send by phone before opening anything. If you cannot contact the send do not open it!
Backing Up Your Files is More Important Then Ever
Make sure you have all of your files backed up both on a local disconnected USB hard drive and in the cloud. There are many free and affordable cloud services available so there is really no excuse not to do this. If your PC gets infected with the Crypto Locker virus you backup may be your digital salvation.
Subscribe to:
Posts (Atom)




