
With more and more ransomware circulating online, it's no longer a surprise when we hear that a new one has been discovered. We recently heard about the extremely dangerous Lockergoga, which caused panic in industrial systems. However, now a new ransomware has appeared, which encrypts its victims' files and at the same time "boosts" the computer!
The reason is VxCrypter, which is based on an old unfinished ransomware, called vxLock, which used Advanced Encryption Standard (AES) and Rivest-Shamir-Adleman or RSA algorithm to encrypt files.
But let's see how this ransomware works.
VxCrypter monitors the SHA-256 of each file. SHA-256 is an algorithm that changes data to a fixed hash. Each file has a unique SHA-256 hash, so a copy of a file will have the same SHA-256 code.
The VxCrypter Ransomware deletes files with the same SHA-256 hash, essentially freeing up space on your computer and improving its performance. This is done to increase the speed of encrypting your files.
So, while affected users will perceive the performance boost as beneficial, in reality the ransomware will encrypt all files on the system even faster. Some of the most common file extensions targeted by the ransomware include .txt, .docx, .xls, .ppt, .zip, .xml, .wmv, etc.
What damage can such attacks cause?
In recent years, attacks using ransomware have become much more frequent and much more damaging, with nearly 70% of ransomware attacks targeting small business owners last year, according to Beazley Breach Response Services.
Very recently, the city of Albany, New York, was hit by a ransomware attack. In the usual blackmail fashion, the hackers demanded a huge ransom to decrypt data files related to birth certificates, marriage licenses, and more.
According to Cybersecurity Ventures, ransomware attacks will amount to $11.5 billion in losses in 2019. Therefore, the right time to improve the security of your devices is now.
