ZCryptor new ransomware spreads like a worm

Microsoft today released a warning for a new variant of ransomware called ZCryptor. The new ransomware ZCryptor (ransom zcrypt.a) has the potential to spread like a worm according to the company.crypt

Once it infects a system, it starts copying itself to a removable disk drive in front of it to spread the infection.

Discover more articles in search results.

In addition to this feature, ZCryptor does not differ much from other ransomware.

Encrypts all files in 88 extensions (Office and archive, image, audio, movie files, logs, database files, APKs, Java, source files, etc.).

Changes their extensions to .zcrypt, and then displays the ransom note (an HTML file that opens with the default browser):ZCryptor

Microsoft says that ransomware usually arrives via e-mail as a disguised executable file, or as an Office file macro.

Immediately after infection, it ensures its presence in the infected system and tries to spread to other systems by making copies of itself. Malware also infects registry entries to load every time the system boots.

The ransomware then tries to communicate with a specific URL from which it receives information and most likely also the key to encrypt the victim's files.

Let's mention again that the best protection for ransomware is the regular backup of your important files, which you should store separately from your main system.

Needless to say, if you are infected with this ransomware, you should know that what USB stick or other removable disk is connected to your system is infected.

Trend Micro


Google preferences

Leave a Comment

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).