Security researchers have identified a new malware targeting online gamers. The new ransomware works like Cryptolocker, and has been dubbed Teslacrypt. It attempts to infect Windows computers by exploiting a vulnerability in Adobe Flash (CVE-2015-0311) or Internet Explorer (CVE-2013-2551).
The malware is distributed via a decoy website that contains an iframe that uses JavaScript. The JavaScript redirects website visitors to other websites until they end up with the Angler Exploit Kit.
Once installed, Teslacrypt scans the system's file system, and encrypts files that match one of the file types included in its code. It then generates a random AES key for each file using OpenSSL code. It uses these keys to encrypt data on the infected computer. It then encrypts the AES keys using a public key consisting of a 2048-bit RSA key pair.
The private key, required to decrypt the per-file keys and ultimately restore the encoded data, is stored on the crooks' command and control server.
Victims must pay a ransom of $500 in Bitcoin, or purchase and surrender a $1,000 Paypal My Cash card using a website hidden on the Tor network.
The command and control servers are also hidden in the Tor network, and maleare communicates with them via HTTP. Teslacrypt also drops the following files on infected machines:
%AppData%\<random> .exe %AppData%\key.dat %AppData%\log.html %Desktop%\CryptoLocker.lnk %Desktop%\HELP_TO_DECRYPT_YOUR_FILES.bmp %Desktop%\HELP_TO_DECRYPT_YOUR_FILES.txt
...and stops any attempt to run the following programs
taskmgr procexp regedit msconfig cmd.exe
An analysis conducted by security firm Bromium Labs shows that TeslaCrypt is very different from Cryptolocker, with the executable code only 8% similar. And while it uses RSA encryption, it appears that the keys are generated on the crooks' systems.
The new malware appears to not only focus on documents or images, but also encrypts files related to more than 20 games and gaming services. The files it encrypts include user profile information in saved games, maps, and mods.
It can hit games like Call of Duty, World of Warcraft, Assassin's Creed, League of Legends, and Minecraft. It also locks Steam accounts and development tools like Unity3D and Unreal Engine.
“The encryption of all these games shows the evolution of crypto-ransomware targeting new markets,” said Vadim Kotov, senior security researcher at Bromium Labs.
“Many young adults may not have any critical documents or source code on their computer (they usually save their photos to Tumblr or Facebook), but most of them certainly have a Steam account with a few games and an iTunes account full of music.”
