An active phishing campaign has been detected by security researchers, which is primarily targeting Australian users, infecting their computers with a new strain of ransomware.
This ransomware contains elements from CryptoLocker and CryptoWall, but its code is completely different.
The malware, also known as Torrent Locker, encrypts specific files on infected computers and then displays a message demanding a ransom to decrypt them – the message is similar to that displayed by the infamous CryptoLocker – for which a free decryption service for the affected files.
However, security experts at iSight Partners point out that the "overall feel of the malware is more reminiscent of Cryptowall.".
Before it begins encrypting data, Torrent Locker creates a secure communication channel with the Command & Control server, from where it downloads a certificate and the files it needs for its configuration.
Researchers observed that, in order to achieve resilience on the infected machine, the malware and its configuration data are stored in the Windows registry.
Additionally, researchers found that, as a sign of goodwill and to reassure the user that this option exists, the malware allows free decryption of a single file.
Torrent Locker is mainly spread through spam and phishing campaigns, so a good way to protect yourself from this threat is to avoid opening emails from unknown senders.

