HomeSecurityAdvanced variant of TeslaCrypt ransomware detected

Advanced variant of TeslaCrypt ransomware detected

The current version of TeslaCrypt cannot be decrypted

TeslaCrypt

Security researchers have identified an advanced variant of the notorious TeslaCrypt, which is being distributed via a well-organized spam campaign.

The threat was first spotted by users of the Bleeping Computer forum, where several cases of unidentified ransomware. After further analysis, researchers concluded that it is a new version of the TeslaCrypt ransomware, which has changes to its code that prevent users from using TeslaDecoder to decrypt their files.

[alert variation=”alert-success”]TeslaDecoder is a free decryption tool for TeslaCrypt victims released by BloodDolly.[/alert]

According to Heimdal Security, the company that analyzed the malicious spam campaign, most infections are located in European countries – and mainly in the Scandinavian countries.

The campaign is based on sending specially crafted emails, which contain a ZIP file as an attachment and ask recipients to settle a supposed payment. Based on the theme of fraud (payment of invoices), researchers estimate that the attackers are not targeting ordinary users, but mainly businesses.

The ZIP file contained in the emails contains a JavaScript file, which, once decompressed and executed, communicates with the C&C server and downloads the TeslaCrypt ransomware in executable file (.exe) format.

This particular version of the ransomware encrypts victims' files in files with .vvv or .zzz extensions and then demands a ransom payment in Bitcoins for their decryption, via a page hosted on a .onion domain on the Dark Web.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS