Ramblings of an old Doc

 

I wrote about CryptoLocker and the fix for it (here, here and here), and CryptoDefender.

Well, I’m here to really make your (Labor) day. After CryptoDefender came Cryptowall for Mac (so you Apple guys wouldn’t feel left out of the joy), and CryptoWall (the baddy on about 600K computers. Oh…and now “TorrentLocker”.

TorrentLocker is a truly deadly piece of malware infecting folks using BitTorrent. While there are ways of getting rid of the others, this one combines CryptoLocker and CryptoWall using BitTorrent keys in the Windows Registry. It’s ransomware, as well.

“A blog report published by iSIGHT Partners says that this ransomware dubbed as TorrentLocker by them is a file encryptor.  Once it infects the system, it encrypts almost all important files and folders using Rijndael algorithm (symmetric cipher). The malware then sends a ransom message which informs the victim that that their files have been encrypted by the "CryptoLocker virus," and the ransom page. iSIGHT Partners also noted that the FAQ section of this malware is similar to CryptoWall malware.” – TechWorm

They named the ransomware 'TorrentLocker' because its configuration resides in the Windows Registry in HKCU\Software\Bit Torrent Application\Configuration.

You can read more about it at the TechWorm link, above. Hopefully, the C&C servers will be found and taken down before more folks are screwed over. As usual they’re asking for $500 for the decryption “key”. If not paid in 48 hrs., the price rises to $1,000.

So far, no fix to this bad one…it is very different at the code level.

Sources:

http://news.techworld.com/security/3541999/cryptowall--ransom-trojan-has-infected-625000-systems-says-dell-secureworks/

http://www.techworm.net/2014/08/torrentlocker-malware-combines.html


Comments
on Sep 02, 2014

Never used bitTorrent or any other file sharing thingy. Too damn risky but I do know a few who do use it. 

on Sep 02, 2014

This newest ransomware hit in Australia, but it will migrate.

Warning to those who use Torrent software...variants will be coming, without a doubt.

on Sep 02, 2014

Anyone who uses torrent programs is just asking for major problems so for all those using those programs heed Doc's advice don't!!

on Sep 02, 2014

Curious.. some games.. particularly World of Warcraft use a torrent mechanism to distribute updates. Wonder if that will get nailed.

on Sep 02, 2014

Oh my, I must be the only living human that doesn't know what bitTorrent is.  I always come away with the feeling that I'm way to old for all of this.  

 

on Sep 02, 2014

Phoon

Curious.. some games.. particularly World of Warcraft use a torrent mechanism to distribute updates. Wonder if that will get nailed.

Some antivirals do also.

on Sep 02, 2014

Philly0381

Oh my, I must be the only living human that doesn't know what bitTorrent is.  I always come away with the feeling that I'm way to old for all of this.  

 
I know alot of people that have no idea what bittorrent or utorrent is and you are not to old just smart if you don't know torrent programs all the better!

on Sep 02, 2014

Torrent's are God's gift to hackers/virii/trojans/identity theft/etc.  They are the computer equivalent of 'fuck me-I'm stupid'.

Intentionally exposing your computer to people you do not know is about as stupid as you can get.....not to mention the act of doing so [joining in the file distribution/sharing] actually COSTS YOU MONEY [unless you're still living at home and your mum pays the ISP - which probably accounts for the MAJORITY of users].

on Sep 02, 2014

Quote went south. Lol

on Sep 02, 2014


Torrent's are God's gift to hackers/virii/trojans/identity theft/etc.  They are the computer equivalent of 'fuck me-I'm stupid'.

Intentionally exposing your computer to people you do not know is about as stupid as you can get.....not to mention the act of doing so [joining in the file distribution/sharing] actually COSTS YOU MONEY [unless you're still living at home and your mum pays the ISP - which probably accounts for the MAJORITY of users].
+1 to Jafo!