HomeSecurityThe journey of the deadliest viruses in history: 2013 – Cryptolocker #21

The journey of the deadliest viruses in history: 2013 – Cryptolocker #21

As our journey through time, through the journey of the most deadly viruses in computer history, slowly comes to an end, we will make a stop in the year 2013 and the dangerous Cryptolocker, which was used for hundreds of thousands of online attacks, before its action was finally suspended by the US intelligence services.

CryptoLocker Ransomeware

CryptoLocker, first appeared in early September 2013, targeting Windows systems. The dangerous ransomware is spread via malicious attachments in spam emails and via the Gameover ZeuS.

Victims of this mutant ransomware do not find their computer locked, but their files are encrypted in such a way that no one can use them. Of course, the encryption key is in the hands of the hackers who blackmail their victims, asking them for money to hand over the decryption key.

The idea is quite lucrative for the crooks, especially if CryptoLocker hits valuable files that aren't stored anywhere else. To ensure that no one can find them, the hackers demand payments in Bitcoin, an untraceable virtual "currency.".

[alert variation=”alert-info”]In most cases, users are asked to pay a sum of $300 to restore their files. However, paying the ransom does not guarantee the decryption of the affected files, as there are numerous reports from victims who were unable to recover their data after paying the required fine. [/alert]

 

Spreading

Cryptolocker is primarily spread via spam emails, as a zip file attachment. The file contains an executable with a PDF icon to trick unsuspecting users into thinking they are opening a simple Adobe PDF.
A common method of spreading ransomware is drive-by-download attacks, where the user is automatically infected by visiting infected websites. The virus exploits vulnerabilities it finds in the user's browser, applications or operating system to install itself automatically, without the user's knowledge.

 

Mode of action

Cryptolocker encrypts all files on the computer using strong 2048-bit encryption. It then informs the user that if they do not pay $300 or €300 within 72 or 96 hours, the encryption key will be permanently deleted, and the files will be lost forever.

[signoff icon=”icon-target”]Cryptolocker uses a sophisticated encryption method, and according to Malwarebytes, if a regular computer tried to break this encryption without the key, it would take about 4 quadrillion years.[/signoff]
The fall of CryptoLocker 

CryptoLocker proved to be extremely profitable for its creators – it is estimated to have yielded between $3 million and $27 million. As expected, such a dangerous malware mobilized the authorities. Soon after its appearance, the relevant authorities from the US, the UK, and most European countries coordinated their efforts in an operation called “Operation Tovar”.

With the coordinated efforts of the authorities, in June 2014 the leader of the hackers who controlled this network was arrested by the FBI, definitively halting the action of the original CryptoLocker.

However, Cryptolocker served as a springboard for the creation and emergence of new and advanced variants of ransomware, which infected and continue to infect the files of millions of users.

freak-encryption-key

And here is where our article for today comes to an end. We still have two more deadly viruses to learn about before we finish our journey. Can you guess who they are…?
to be continued
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS