HomeinetBitCrypt v2: all about the new threat

BitCrypt v2: all about the new threat

A new ransomware variant named BitCrypt that encrypts files and demands a ransom in bitcoins from its victims has appeared online.

bitcrypt

BitCrypt is part of a growing category of malicious programs known to the public as ransomware that aim to extort money from their victims by locking their files or their computers.

One of the first variants of BitCrypt appeared in February and is inspired by the success of a similar program called Cryptolocker. Cryptolocker has infected over 250,000 computers in the last three months of 2013 alone.

Just like Cryptolocker, once installed on a system, BitCrypt encrypts many files, documents and photos, applications and database files. Its victims risk losing access to their personal files or anything else they have on their computer if they have not kept backups.

While the first variant of BitCrypt used a relatively strong RSA-1024 encryption, security researchers from Airbus Defence and Space identified serious shortcomings in the malicious application that allowed them to develop a decryption program for the infected files.

However, according to Trend Micro security researchers, an improved version of the malware appeared this month and is likely designed for widespread distribution. The new version adds a bitcrypt2 extension to the encrypted files and can display the ransom note in 10 different languages: English, French, German, Russian, Italian, Spanish, Portuguese, Japanese, Chinese and Arabic.

When this variant infects a computer it changes the desktop wallpaper to an image that says “Your computer has been infected by the BitCrypt v2.0 cryptovirus” and shows the victim a file named Bitcrypt.txt for additional instructions, as reported by Trend Micro researchers.

The text file contains information about how victims can gain access to a specific website that is hidden on the Tor network, in order to download a special decryption program. The website asks users for 0.4 bitcoins – approximately 230 dollars at the current cryptocurrency price.

Trend Micro researchers also found that the new variant of BitCrypt is distributed by a Trojan called FAREIT and is designed to steal bitcoins.

FAREIT, as soon as it enters a computer, begins searching for wallet.dat (for Bitcoin), electrum.dat (for Electrum) and .wallet files (MultiBit), researchers say. These files are created and used by different Bitcoin client applications.

To avoid falling victim to ransomware and being forced to pay to recover your files, it is important to regularly create backups of your data. Preferably not on the same computer or a shared network drive, because the malicious software could affect those backups.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS