TorrentLocker ransomware, also known as Crypt0L0cker or CryptoLocker, continues to infect users, two years after it was discovered and analyzed by security researchers for the first time.
Considering that most ransomware families disappear after a few weeks and very few persist for over a year, this is remarkable, but in a bad way, at least for us regular users.
What's even stranger is that TorrentLocker is doing it with minimal changes to its recipe for success, if we are to believe a technical report published last week by ESET, the cybersecurity vendor based in Slovakia.
The company's experts say that they have identified several changes to the way TorrentLocker operates, but overall, it's still the same tool that was active two years ago. So why hasn't it been stopped? Because it's a very well-written piece of ransomware, with very few bugs, and because it uses very strong encryption.
All files that have been infected with TorrentLocker are locked with an AES-256-CBC algorithm first, and then the key to unlock this encryption is also locked with a double-key RSA algorithm, which keeps one key on the computer and sends the other to the C&C server of the scammer.
The way C&C servers are used is one of the changes observed in TorrentLocker operations, explain the ESET researchers. Even if communication with these servers is encrypted, security researchers often locate them and arrange for them to be taken down by the hosting provider or with the help of authorities.
To avoid such scenarios and leave infected victims in a position to pay the ransom so that the crooks can profit from spam campaigns , recent versions of TorrentLocker come with a list of .onion URLs, websites accessible via the Tor network, through which the ransomware resurfaces when its main C&C servers go down.
It is not the only malware family that has launched the Tor application as a C&C backbone network. The Ursnif trojan has done the same.
Aside from Tor as a backup C&C communication channel, TorrentLocker will also check the victim's IP address and display the corresponding ransom note in the user's language.
The ransomware will display the customized ransom note for 22 countries, even if recent spam campaigns have not targeted them all yet.
According to ESET, the group behind TorrentLocker uses spam emails disguised as an invoice for a local utility company and targets users in countries including Australia, Austria, Czech Republic, Denmark, Germany, Italy, Netherlands, Norway, Poland, Spain, Sweden, Switzerland, Turkey, and the United Kingdom.
ESET says, also, that TorrentLocker is written in such a way as to avoid countries such as China, Russia, Ukraine and oddly also the USA, which seem to be the favorite target of almost all ransomware variants.


