The latest version of CryptXXX ransomware came with many changes, the most significant of which is an infostealer module that can cause a dump and steal passwords from various applications on the infected machine.
Called StillerX, this module was considered part of CryptXXX starting with version 3.100, which was first detected by Proofpoint on May 26
The US security firm says this CryptXXX version comes with many new features, but StillerX makes it more dangerous than before.
StillerX works just like classic password dumpers, also known as infostealers. These types of malware are specifically designed to attack internal databases of various software packages, extract encrypted passwords or plaintext passwords, and then send them to an online server.
CryptXXX's StillerX module is capable of targeting all kinds of software , such as browsers, download managers, email clients, FTP software, IM applications, poker applications, proxy clients, VPNs, dialer credentials, and passwords stored in the cache of WNetEnum and Microsoft 's Credential Manager .
Users can detect a CryptXXX ransomware infection originating with StillerX by the presence of the “stiller.dll,” “stillerx.dll” and “stillerzzz.dll” files on their systems.
Proofpoint says there are indications in the StillerX code that lead them to believe the module could be used as a standalone, without CryptXXX.
In addition to its ability to steal your passwords for future cyber attacks, CryptXXX has also changed its decryption website. The portal has received a facelift and now features new graphics.
Until now, the ransomware used the same user interface as the CryptoWall ransomware.
In closing, CryptXXX is now able to search for network-attached drives and infect files it finds on partitions. The ability to search for and infect network drives has appeared in several ransomware families in recent weeks and seems to be the natural course of evolution for most of these threats, in an attempt to maximize their impact and the power of their victims to pay the ransom.
Since CryptXX first appeared in April this year, Kaspersky has managed to crack CryptXXX 1.x and then CryptXXX 2.x. CryptXX 3.100, however, is again undecryptable, destroying the Russian company's free decryption tool.


