A ransomware family called CTB-Faker is trying to pass itself off as one of the more famous variants called CTB-Locker and lies to users that it uses the strongest encryption when in reality it does nothing more than move all of the victims' data inside password-protected ZIP files.

The good news is that this ransomware is decryptable, albeit through a complicated process that regular users may need help with.
The second good news is that Lawrence Abrams has volunteered to help users with the decryption process for free.
According to technical analysis by Bleeping Computer and Check Point, CTB-Faker is distributed via adult websites that promote striptease videos.
Users are encouraged to download a ZIP file, which contains an executable. Running the executable launches the CTB-Faker ransomware, which will slowly move the files to another password-protected file, located at “C:\Users.zip.”
To move the files and then password-protect them, the CTB-Faker archive uses the WinRAR application. Once the ransomware creates this file, it forces the computer to reboot, and then, when the user logs in, it displays the ransom note.
The ransom note is specifically designed to resemble the same note used by the more famous CTB-Locker ransomware.
The strategy seems to be working, as it was reported that a Bitcoin address used for the ransom from the CTB-Faker note received 577 Bitcoin ($381,000) in payments.
It has not yet been confirmed that all of the Bitcoin funds came from the CTB-Faker payments, but considering the fact that the ransomware authors are asking for 0.08 Bitcoin ($50) per infected computer, that would mean that CTB-Faker has infected over 7,200 users. Nevertheless, for such a simplistic variant of a ransomware, the crooks seem to be getting results from their investment.
