Critoni new ransomware for sale

A new ransomware named Critoni, has appeared and is available for sale on underground forums. Vendors advertise it as a new generation of Cryptolocker that uses the Tor για να κρυπτογραφήσει την επικοινωνία του με το διακομιστή διοίκησης και ελέγχου, ούτως ώστε να παρέχει ανωνυμία.

His purpose υ κιτ είναι να κρυπτογραφήσει διάφορους τύπους αρχείων, όπως έγγραφα και εικόνες, και μετά να ζητήσει for their decryption.

Critoni

The sale announcement was discovered by a French security researcher using the pseudonym Caffeine. The researcher says that advertising has been published since mid-June, and that it was primarily used primarily for purposes in Russia. Continuing on, the researcher says he has recently begun to be used in other countries.

Malware has been named by criminals CTB-Locker (Curve-Tor-Bitcoin Locker), and is detected as Critoni.A by Microsoft. Its purchase price reaches 3.000 dollars.

Critoni is advertised to use persistent cryptography based on elliptic curves, which makes it impossible to decrypt the file. Encryption keys are created randomly.

ctb offline

As the name implies, the ransom has to be paid in Bitcoin digital coins to prevent criminals from locating the transaction. If the victim does not have bitcoins, criminals provide instructions on how to obtain.

The publication in the underground forum also indicates that the encryption process can be done without an Internet connection.
According to her security experts Kaspersky, this is the first cryptomalware that the Tor network uses to communicate with the administration and control server. This kind of protection has been observed in bank Trojans.

EK payload : Spambot it seems.
079bf937d5020ca77ff97a5318414f07
2nd Stage Payload: Critroni.A
e89f09fdded777ceba6412d55ce9d3bc

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).