HomeSecurityHDDCryptor Ransomware locks hard drive boot files

HDDCryptor Ransomware locks hard drive boot files

Researchers have identified a new ransomware family that attacks the MBR (Master Boot Record) of a hard drive and prevents computers from booting after encrypting their files. The ransomware is called HDDCryptor (or Mamba) and has been around since January 2016, according to a thread on the Bleeping Computer forum, where users reported their infections.

HDDCryptor Ransomware locks hard drive boot files

Technically, HDDCryptor predates the overhyped Petya, and later the Satana ransomware family, which received much more media attention and behaved in the same way, rewriting the MBR and preventing the PC from booting.

Based on available reports, it appears that a recent malware distribution campaign is delivering a new version of HDDCryptor to users around the world.

The first to (re)detect HDDCryptor was Renato Marinho, a security researcher at Morphus Labs, who said his company was called in to investigate a massive HDDCryptor infection at a multinational, which affected its headquarters in the US, Brazil, and India.

Marinho's initial technical analysis was followed a few days later by another one at Trend Micro, mostly identical.

According to both, HDDCryptor infections began with users accessing a malicious website and downloading malware-infected files onto their computers. These files were either infected with HDDCryptor directly or came with an intermediate malware that delivered HDDCryptor at a later stage, once the crooks were sure they had boot persistence on the infected computer.

first screen

The actual HDDCryptor payload is several binaries all rolled into one. When the large binary is executed, it “drops” files onto the user’s computer and causes them to launch in a specific order.

HDDCryptor first scans the local network for network drives. It then uses a free tool called Network Password Recovery to search for and dump the credentials of shared network folders, current or past.

The process continues by running another open source tool called DiskCryptor to encrypt the user's files found on partitions . This tool is then used in conjunction with the previous scan and passwords to connect to network drives and encrypt the data.

Finally, HDDCrypter rewrites the MBR with a custom boot loader and reboots the computer, which then gets stuck on a ransom note, like the one below:

ransomware-note

Users are encouraged to contact the ransomware author via e-mail, where they will receive a Bitcoin addressto which they must pay the ransom. The crooks are currently asking for 1 Bitcoin (≈ $610).

According to funds found in one of the Bitcoin addresses shared in these emails, at least four people appear to have paid the requested amounts so far, but there are potentially more if scammers are using different Bitcoin addresses.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS