Cryptolocker malware (Trojan.Cryptolocker) was considered a success by cybercriminals. But everything shows that they are not stopping there. Malware developers have turned their attention to developing new ransomware malware. The sophisticated CryptoDefense (Trojan.Cryptodefense) is one such malware.

CryptoDefense , Symantec’s telemetry shows that the company’s software has blocked over 11,000 unique CryptoDefense infections. Using Bitcoin addresses provided by the malware’s creators for ransom payments and looking at publicly available Bitcoin blockchain information, the company estimates that this malware earned cybercriminals over $34,000 in just one month (based on the value of Bitcoin at the time of writing).
“Imitation is not only the most sincere form of flattery but also the most sincere form of learning” – George Bernard Shaw.
CryptoDefense, in essence, is a sophisticated hybrid design that incorporates a number of effective techniques that have been used in the past by other ransomware malware developers to extort money from victims. These techniques include using Tor and Bitcoins for anonymity, encrypting files using strong RSA 2048 encryption, and using pressure tactics such as threats of increased costs if the ransom is not paid within a short period of time. Symantec has observed that CrytoDefense arrives via email. If someone makes the mistake of opening the file, (usually a .PDF) CryptoDefense will install itself on their computer and immediately attempt to contact one of the following remote domains.
Once the remote site responds, the malware activates the encryption and sends the private key back to the server. Once the remote server confirms receipt of the private decryption key, the malware sends a screenshot of the infected computer’s desktop to the malicious user. Once it encrypts the victim’s files, CryptoDefense creates the following files in each folder containing encrypted files: HOW_DECRYPT.TXT HOW_DECRYPT.HTML HOW_DECRYPT.URL The authors of the malware use the Tor network to pay the ransom. If the victim is not familiar with the Tor network, they provide further instructions on how to download a Tor browser and how to type in the unique Tor address to go to the payment website. Using the Tor network hides the location of the website and provides anonymity to the attacker. Once the user opens the unique personal payment page, and “deposits” the ransom, they will receive the unique decryption key. It is worth noting that the ransom demanded by the malware developers is around $500 and must be paid within four days or the price doubles. The use of this time pressure tactic by cybercriminals gives victims less time to react.
