A new wave of spam messages linked to the Critroni file-encryption malware aims to trick unsuspecting recipients and is supposedly about an update for the Chrome web browser that is available at a location provided in the message.
Critroni , also known as CTB-Locker , is a ransomware that encrypts data on the infected system and then displays a message asking the victim for money to unlock their files .
According to Jerome Segura from Malwarebytes, the malicious payload has been retrieved from websites that appear to have been compromised by cybercriminals to host the malware.
The threat relies on a dynamic redirect mechanism, which has been determined to be at assetdigitalmarketing[.] Com/redirect PHP[.]. What the victim receives is a file that pretends to be an installer for Google Chrome. Once the file is executed, the encryption process begins and the ransom message is displayed when the operation is complete.
Data recovery without paying the ransom can be achieved if it is an older variant of the malware, which does not delete the shadow copies created by the Windows Volume Shadow Service. In case this is not the case, the data can be recovered using programs such as Shadow Explorer. However, not all variants have this flaw.
One of the latest versions of Critroni comes with an extended grace period for executing the Bitcoin payment, 96 hours instead of the original 72 hours, but it also has higher financial requirements, a few hundred dollars, instead of the 50 it was asking for in the summer of 2014.
It also has versions of the ransom message in multiple languages and offers the ability to decrypt a set of five items, as a sign of good faith.
Malwarebytes appears to have detected the latest version of the ransomware ( detected as Trojan.ZBAgent.NS ), as the payment request is for 2 bitcoins (currently around $450/€400) and the deadline is 96 hours. When the waiting time expires, the key that decrypts the data is deleted from the server and the victim is left with the encrypted files.
Regarding this scam in particular, users should be aware that Google Chrome is activated automatically in the background, without user intervention. The entire process is seamless and the new version is available when the user restarts the application.
Mozilla Firefox an automated update process, while Internet Explorer receives the latest update through Windows Update.
Notifications for a new version of the program are not delivered via email and most often notifications appear in the program. Therefore, before users rush to download an updated version via a link provided in an email, it is best to check if the new update is available for the application in question.

