HomeSecurityCryptoLocker variant targets Japanese users

CryptoLocker variant targets Japanese users

Researchers have found that a version of TorLocker, a piece of crypto-malware related to CryptoLocker, is being distributed to Japanese-speaking users.

CryptoLocker Variant
Once the malware is installed on the system, it encrypts files with certain extensions, keeping them locked until a ransom is paid by the victim in exchange for their decryption.

The ransom demanded by cybercriminals is stated in a message that appears after data is encrypted and ranges between $500 / €400 and $3,600 / €2,900.
TorLocker is part of a larger operation

Symantec confirms that there are multiple variants of this particular threat currently targeting Japanese people.

The company explains in a blog post that the malware is part of a broader design that offers cybercriminals the ability to create a custom ransomware from a malware buildingtoolkit.

Additional options available in the program include access to the TorLocker, which provides information on the number of infections. In return, crooks who use the infrastructure must share a percentage of the profits with the program administrators.

Researchers say that Japanese variants of the ransomware are distributed through unsafe websites.

Users were misled via a supposed Flash Player installation page

In one case, TorLocker to be distributed from a compromised website, which presented a fake download page for Adobe Flash Player.

Misled users received a file that did not even bear the distinctive Adobe Flash icon, a clear indication that the executable was not the actual Flash installation file.

After the encryption process is complete, the victim is presented with a ransom message in Japanese, demanding payment in Bitcoin.

Security experts recommend that victims not comply with the extortion demands because the attackers cannot offer the means to decrypt their files once they receive the money. This type of criminal activity is also discouraged if the money is not paid, as there is no incentive for scammers to participate in such campaigns.

The best method of protecting users against these threats is to create a backup so that, in the event of an attack, files can be restored.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS