ESET's investigations reveal details of the CTB-Locker.

ESET researchers have identified a new type of cyberattack spreading across Europe and Latin America. The cause is a variant of the ransomware family known as CTB-Locker .
The following is information about the CTB-Locker as listed in the announcement sent by ESET:
CTB -Locker encrypts user files like CryptoLocker, demanding a ransom in Bitcoin. According to ESET's research, the campaign has just begun. More information about CTB-Locker is available on ESET's WeLiveSecurity.com information page.
Early Tuesday, 1/20/2015, the ESET Latin America Research Team repeatedly detected activity of CTB-Locker, a filecoder detected by ESET telemetry as Win32/FileCoder.DA.
The infection begins when the victim receives an e-mail with the subject "fax", with an attachment that looks like a fax copy.
The embedded file is infected with Win32/TrojanDownloader.Elenoocka.A – a trojan downloader that attempts to connect to the Internet to “download” other malware – in this case Win32/FileCoder.DA, also known as CTB-Locker. If executed on the victim’s device, CTB-Locker encrypts specific files on the device, locks the screen, and displays a ransom message.
ESET researchers also found a similarity between CTB-Locker and CryptoLocker: “Both have a similar pattern of encrypting victims’ files and differ only in the encryption algorithm used,” notes Pablo Ramos, Head of Research at ESET in Latin America. Also, as with CryptoLocker, the victim is asked to pay a ransom in Bitcoin – approximately 8 Bitcoins (estimated value of approximately $1,680).
The best way to protect yourself is the well-known security trifecta – backing up files, updating software, and protecting the device.
"The results of a CTB-Locker attack on a company or user who does not have a backup solution can be a real headache. In reports, we have seen companies pay thousands of dollars to recover their data," concludes Ramos.
