HomeSecurityCryptoFortress: New ransomware with file encryption capabilities

CryptoFortress: New ransomware with file encryption capabilities

CryptoFortress is a new ransomware with file-encrypting capabilities. It resembles TorrentLocker, but its internal mechanism shows a different malware structure.

The ransom message that appears to the victim when the data on the computer has been encrypted is similar to the one seen in TorrentLocker, which as we mentioned is borrowed from CryptoLocker. Similarities were also found on the payment page.

CryptoFortress

Security researchers report that the developers of CryptoFortress took the HTML templates and CSS code from TorrentLocker. However, the similarities do not stop there, since the code and encryption system available in the new ransomware, as well as the distribution method, are not the same.

ESET researchers (identifying it as Win32/Kryptik.DAPB) created a list of all the commonalities found in the encryption malware it uses, and apart from the encryption algorithm (AES-256), the AES key encryption (RSA-1024) and the fact that the payment page is hidden on the anonymous Tor network, they don't have much in common.

CryptoFortress is spread through exploit kits, not spam emails. The location of the ransom page is in the malware code, not in the command and control (C&C) center.

Additionally, the cryptographic library used by CryptoFortress is Microsoft's CryptoAPI, while TorrentLocker uses the open-source LibTomCrypt.

Another difference lies in the fact that the new malware encrypts the first half of the file or up to 5MB and the ransom amount it demands is around $500, which must be paid in Bitcoin.

The first report of CryptoFortress appeared earlier this month by malware researcher Kafeine, who tracks exploit kit changes. One indication of the infection is that the files use the extension “FRTRSS.”

Analysis by security researchers at security firm Lexsi revealed that the AES key used to encrypt the data on the hard drive was stored locally in the HTML file (the file is called “READ IF YOU WANT YOUR FILES BACK”), and is protected by a strong public-key (RSA 1024).

In addition to local drives, the ransomware also targets mapped drives and network shares, essentially destroying everything it encounters. It favors backups to prevent file recovery.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS