Cryptolocker ransomware infecting around 250,000 computers in the UK

Bitcoins
Virtual crime for very real virtual cash

A security research team has revealed that Cryptolocker, a new form of ransomware, may have managed to infect anywhere between 200,000 to 250,000 devices and could have collected over $980,000 (£600,000, AU$1,000,000) in Bitcoins.

Dell SecureWork's counter-threat unit has examined the infection rates of the Cryptolocker malware and claims that it has been developed in either Russia or Eastern Europe. The earliest infection this year would have happened around September 5 this year. How the malware is distributed is still not clear.

Ransomware is a successful new breed of malware and virus that finds and locks away essential files on a victim's computer. The encrypted files are held locked away until the user meets the demands of payment within 72 hours – displayed ominously in the form of an on-screen timer. It targets mapped drives, Dropbox files, and all locally connected, network attached or cloud-based storage.

"Difficult to circumvent"

Unlike traditional malware and viruses, which can be removed via the use of antivirus programs, Cryptolocker cannot be removed. If a user does attempt to root out the virus there is still no way to access the files it encrypts. All decryption keys are located on one of Cryptolocker servers. Only if the user pays the ransom are the files released again.

"By using a sound implementation and following best practices, the authors of Cryptolocker have created a robust program that is difficult to circumvent," SecureWorks notes in a blog post. "Instead of using a custom, cryptographic implementation like many other malware families, Cryptolocker uses strong third-party certified cryptography offered by Microsoft's CryptoAPI."

Strangely Cryptolocker also has its own dedicated support system for people who pay their ransom but miss the deadline. There have been reports of the author of the program actively answering help question on online forums, including this thread.

SecureWorks estimates that the ransomware has infected 250,000 systems in the first 100 days of its life.

TOPICS
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired