CryptoFortress is a new ransomware with file-encrypting capabilities. It resembles TorrentLocker, but its internal mechanism shows a different malware structure.
The ransom message that appears to the victim when the data on the computer has been encrypted is similar to the one seen in TorrentLocker, which as we mentioned is borrowed from CryptoLocker. Similarities were also found on the payment page.
Security researchers report that the developers of CryptoFortress took the HTML templates and CSS code from TorrentLocker. However, the similarities do not stop there, since the code and encryption system available in the new ransomware, as well as the distribution method, are not the same.
CryptoFortress is spread through exploit kits, not spam emails. The location of the ransom page is in the malware code, not in the command and control (C&C) center.
Additionally, the cryptographic library used by CryptoFortress is Microsoft's CryptoAPI, while TorrentLocker uses the open-source LibTomCrypt.
Another difference lies in the fact that the new malware encrypts the first half of the file or up to 5MB and the ransom amount it demands is around $500, which must be paid in Bitcoin.
The first report of CryptoFortress appeared earlier this month by malware researcher Kafeine, who tracks exploit kit changes. One indication of the infection is that the files use the extension “FRTRSS.”
Analysis by security researchers at security firm Lexsi revealed that the AES key used to encrypt the data on the hard drive was stored locally in the HTML file (the file is called “READ IF YOU WANT YOUR FILES BACK”), and is protected by a strong public-key (RSA 1024).
In addition to local drives, the ransomware also targets mapped drives and network shares, essentially destroying everything it encounters. It favors backups to prevent file recovery.
Source: secnews.gr

