Locker: Sophisticated Ransomware Infects Computers and Acts at a Predetermined Time
Security researchers have identified a ransomware with file-encrypting capabilities, called Locker, which enters compromised computers in a dormant state and activates at a specific time interval set by the attacker.
This approach has not been detected in other malware of the same type, and it is unclear why the attackers delay the process of encrypting victims' files.
A possible explanation is that perhaps the distribution of the ransomware began before the creation of the necessary infrastructure to store the decryption keys for the files and deliver them to the victims who pay the requested ransom.
Furthermore, by adopting this method, crooks make it more difficult to trace the time of infection and the distribution methods of the malware, which is spread through spam emails that link to a malicious site hosting the Locker or through drive-by attacks based on malicious ads and compromised websites.
According to an analysis by Bleeping Computer, files on computers infected with Locker began to be encrypted on May 25 at midnight (local time). Unlike similar threats, Locker does not change the extension of affected files, which appear untouched until the user opens them.
Additionally, the malware deletes the copies created by the Windows Shadow Copy service, but only on the system drive. Files stored on any other partition can be recovered. Additionally, there are reports that deleting “Shadow Copies” is not always successful and data can be restored with special software.
After encrypting all data (mainly documents and images), Locker displays the ransom message, demanding 0.1 bitcoins ($24/€22) in exchange for the decryption key, which is stored on a server hidden in the Tor anonymity network.
📧
Subscribe to the SecNews Newsletter

