Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Better Encryption Makes CryptoLocker a Threat

    Written by

    Robert Lemos
    Published November 29, 2013
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      For two months, a pernicious piece of malware has spread to consumer and business computers, encrypting files and demanding payment for the key to unlock the information.

      The malware, known as CryptoLocker, or Crilock, gains a foothold in networks when unwary Windows users open an attachment in an email that appears to be a customer complaint. The malware contacts a server on the Internet from which it downloads a unique code key and then encrypts the most important files on the infected computer, displaying a message to the user demanding a ransom for the key to unlock their data.

      Known as ransomware, such programs are not new, but the latest version has raised the bar among the category of malicious software, Nick Levay, chief security officer of Bit9, told eWEEK. In the recent past, ransomware has typically just used a variety of tricks or weak encryption to lock a system, whereas CryptoLocker uses strong encryption and gives users a deadline to pay up.

      “In the past, the user would go to their go-to IT guy and get the stuff cleaned up pretty quick,” he said. “But CryptoLocker actually has some teeth.”

      Ransomware is not a new type of attack. In 1989, a program that purportedly taught users about AIDS and HIV locked the host system when it ran for the 90th time, encrypting filenames and directories, and demanding $378 for the unlock code. Fortunately, the encryption algorithm implemented in the virus was extremely weak, and the program reused the same key, so security firms were able to work out the unlock code, according to a post by Paul Ducklin, head of technology for security firm Sophos.

      “This century’s ransomware has lifted the bar rather dramatically,” he wrote. “The crooks scramble your files using strong encryption with a randomly-chosen key. Then they send the key to themselves, using a secure upload.”

      In 2008, a program known as GPCode encrypted files and demanded ransom for the key. Security firm Kaspersky Lab found a way to break the 660-bit RSA key and provided tools to affected consumers to recover their data. Soon after, the criminals behind GPCode upgraded the key strength to 1,024 bits, making it much more difficult, if not impossible, to recover the key.

      First detected by security firms in September, CryptoLocker improves on that approach, downloading a unique key for each infection using a server linked to a randomly generated domain name. Typically, using a domain generation algorithm (DGA) makes it more difficult for security firms to enumerate and block the domains used by malware to communicate with their criminal operators, but security firm OpenDNS has been able to calculate many of the domain names and has begun blocking them. While such a tactic does not prevent an infection, it does block the malware from encrypting the affected PC’s files.

      “We are not doing the traditional tactic of preventing the binary from coming down,” Dan Hubbard, chief technology officer of OpenDNS, told eWEEK. “In most cases, the machine has already run the binary, and now it is trying to beacon out and get the encryption key. We disconnect that channel.”

      The program has likely infected thousands of computers, according to data from Kaspersky Lab. More than 2,700 computers attempted to contact the domains that served up the encryption keys to infected systems, according to the firm.

      As the first line of defense against ransomware, companies need to keep good backups, experts said. In addition, protecting machines with updated antivirus programs and training employees to look critically at potential phishing email messages can help.

      While the criminals behind CryptoLocker have reportedly sent keys to those victims who have paid the ransom, security experts stress that paying up supports the criminals’ model and will lead to more attacks in the future.

      “People have to be encouraged not to pay,” Bit9’s Levay said.

      Robert Lemos
      Robert Lemos
      Robert Lemos is an award-winning journalist who has covered information security, cybercrime and technology's impact on society for almost two decades. A former research engineer, he's written for Ars Technica, CNET, eWEEK, MIT Technology Review, Threatpost and ZDNet. He won the prestigious Sigma Delta Chi award from the Society of Professional Journalists in 2003 for his coverage of the Blaster worm and its impact, and the SANS Institute's Top Cybersecurity Journalists in 2010 and 2014.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×