'CryptoLocker' malware holds computer files for ransom - WFLA News Channel 8

'CryptoLocker' malware holds computer files for ransom

Posted: Updated:
CryptoLocker displays this message on infected computers. Courtesy: YouTube CryptoLocker displays this message on infected computers. Courtesy: YouTube
NEW YORK, NY (WFLA) -

CryptoLocker, a new and nasty piece of malicious software is infecting computers around the world – encrypting important files and demanding a ransom to unlock them. 

According to Sophos, the worldwide digital security company, it’s been hitting pretty hard for the past six weeks or so.

“It systematically hunts down every one of your personal files – documents, databases, spreadsheets, photos, videos and music collections – and encrypts them with military-grade encryption and only the crooks can open it,” said Chester Wisniewski, a senior security advisor at Sophos.

Even though it’s infected, your computer keeps working normally; you just can’t access any of your personal files. It’s scary, especially if you haven’t backed-up your data.

Cybercrime is evolving, as the bad guys get smarter and use newer technologies,” noted Michael Kaiser, executive director of the National Cyber Security Alliance. “They’re always looking for new ways to steal your money.”

CryptoLocker is different from other types of “ransomware” that have been around for many years now that freeze your computer and demand payment. They can usually be removed which restores access to your files and documents.

Not CryptoLocker – it encrypts your files. There’s only one decryption key and the bad guys have that on their server. Unless you pay the ransom – within three days, that key will be destroyed. And as the message from the extorters says” “After that, nobody and never will be able to restore files…”

The typical extortion payment is $300 USD or 300 EUR paid by Green Dot MoneyPak, or for the more tech savvy, two Bitcoins, currently worth about $400.

To instill a sense of urgency, a digital clock on the screen counts down from 72 hours to show much time is left before that unique decryption key is destroyed.

One victim described his anguish in an online post: “The virus cleverly targeted …all of our family photos, including all photos of my children growing up over the last 8 years. I have a distraught wife who blames me!”

This sophisticated malware is delivered the old-fashioned way – an executable file hidden inside an attachment that looks like an ordinary ZIP file or PDF. One small business reports being compromised after clicking on an email attachment that was designed to look like a shipping invoice from the U.S. Postal Service.

Open that file and bad things start to happen, although it may take several days for the ransom demand to pop up on your screen after the machine is infected.

“The author or this (malware) is a genius. Evil genius, but genius none the less,” an IT professional commented in an online tech forum. Another wrote, “This thing is nasty and has the potential to do enormous amounts of damage worldwide.”

Good anti-virus software can remove the CryptoLocker malware from your computer, but it cannot undo the damage – the encryption is that good.

“It’s the same type of encryption used in the commercial sector that’s approved by the federal government,” Wisniewski told me. “If the crooks delete that encryption key, your files are gone forever – even the NSA can’t bring them back.”

Victims large and small

The cyber-crooks are targeting both businesses and individual computer users – anyone who will pay to regain access to their files.

The CryptoLocker forum on BleepingComputer.com is filled with page after page of horror stories. Here is a small sample:

“When we discovered the infection from a user’s workstation on the network, this program had encrypted over 180,000 files through the network shares in a period of 6 days. I pretty much shut down the business for 2 days after we realized what was happening.”

“Our company was infected this morning. The virus hit a machine 4 days ago and today we got the pop up about the ransom. All files on the network drive the user had access to are now encrypted.”

“We had a workstation get infected yesterday that encrypted everything on our network share drive. We had backups, although they weren’t recent enough, so despite all feelings against it, we paid the ransom and everything started to decrypt overnight.”

Of course, there’s no guarantee there will be a happy ending if you pay the ransom. And then there’s the bigger issue – by doing this, you’re helping fund a criminal operation.

“It encourages them to continue this bad behavior,” said Howard Schmidt, former White House Cyber Security Advisor and a co-founder of Ridge-Schmidt Cyber. “As people pay the ransom, the bad guys have the money to reinvest in create research that are more virulent and hide better from detection.”

How to protect yourself

Go on the Internet and there’s no way to guarantee malware won’t make it onto your computer – even if you follow all the rules of safe computing. So you need to act defensively, and that means regular backups.

“Backup, back, up, back up,” said Schmidt. “That’s the only way to reduce the risk of losing your files forever.”

If you have a recent backup, you can recover from CryptoLocker and other malware with no serious consequences. That backup should be a snapshot of everything on the system and not a simple synchronization, as happens with most automated external hard drives and many cloud-based services.

With these synchronized backups, stored files that have changed on the master drive are overwritten with the new ones. If a malicious program encrypts your master files, those backups would also be encrypted – and useless. Your backup should be disconnected from your computer until the next time you need to access it.

More Info:

TODAY.com and NBC News contributor Herb Weisbaum contributed to this report.

Do you tweet? We do! Join us on http://8.wfla.com/1dsYrjS

  • NewsMore>>

  • Dog beach at center of Pinellas condo conflict

    Dog beach at center of Pinellas condo conflict

    Sunday, April 20 2014 2:32 PM EDT2014-04-20 18:32:02 GMT
    The popular canine park is located on Sunset Beach in Treasure Island. The popular canine park is located on Sunset Beach in Treasure Island.
    Dog owners and residents of a Pinellas County condominium complex are in a dispute over a popular dog park.The park, on Sunset Beach off Treasure Island, has been frequented by dog owners for years because it is one of the few places in Pinellas County where dogs and their owners can legally access the water.
    Dog owners and residents of a Pinellas County condominium complex are in a dispute over a popular dog park.The park, on Sunset Beach off Treasure Island, has been frequented by dog owners for years because it is one of the few places in Pinellas County where dogs and their owners can legally access the water.
  • Boxer Rubin 'Hurricane' Carter dies at 76

    Boxer Rubin 'Hurricane' Carter dies at 76

    Sunday, April 20 2014 2:22 PM EDT2014-04-20 18:22:44 GMT
    Former midddleweight boxer Rubin Carter has died. (Source: Flickr) Former midddleweight boxer Rubin Carter has died. (Source: Flickr)
    Rubin "Hurricane" Carter, the boxer whose wrongful murder conviction became an international symbol of racial injustice, has died at 76.
    By GREG BEACHAM AP Sports Writer Rubin "Hurricane" Carter, the boxer whose wrongful murder conviction became an international symbol of racial injustice, died Sunday. He was 76.
  • Good Samaritan renders aid to man in Tarpon Springs crash

    Good Samaritan renders aid to man in Tarpon Springs crash

    Sunday, April 20 2014 1:16 PM EDT2014-04-20 17:16:38 GMT
    The crash occurred on Keystone Rd. in Tarpon Springs on Saturday night. The crash occurred on Keystone Rd. in Tarpon Springs on Saturday night.
    A Good Samaritan helped save the life of a 52-year-old Holiday man Saturday night after he lost control of his vehicle and landed in a pond in Tarpon Springs.Richard Fenton was transported to St. Joseph’s Hospital in Tampa where he is listed in serious condition.
    A Good Samaritan helped save the life of a 52-year-old Holiday man Saturday night after he lost control of his vehicle and landed in a pond in Tarpon Springs.Richard Fenton was transported to St. Joseph’s Hospital in Tampa where he is listed in serious condition.
  • Sign up for WFLA News Channel 8 Email Alerts

    * denotes required fields






    Thank you for signing up! You will receive a confirmation email shortly.
  • Most Popular StoriesMost Popular StoriesMore>>

  • VIRAL VIDEO: Selfie Captures Man Getting Kicked By Train Engineer

    VIRAL VIDEO: Selfie Captures Man Getting Kicked By Train Engineer

    Wednesday, April 16 2014 2:46 PM EDT2014-04-16 18:46:32 GMT
    A video posted to YouTube showing a man getting kicked in the head by a person on a passing train has gone viral.
    A video posted to YouTube showing a man getting kicked in the head by a person on a passing train has gone viral.
  • Arcadia dog set on fire improving, could be released early

    Arcadia dog set on fire improving, could be released early

    Tuesday, April 1 2014 11:26 PM EDT2014-04-02 03:26:55 GMT
    "Hope" was doused with kerosene and set on fire. BluePearl Veterinary photo"Hope" was doused with kerosene and set on fire. BluePearl Veterinary photo
    A 1-year-old DeSoto County dog that was set on fire is improving and could be released from 24-hour care to a primary care veterinarian next week.
    A 1-year-old DeSoto County dog that was set on fire is improving and could be released from 24-hour care to a primary care veterinarian next week.
  • Trending: World's most haunted island up for auction

    Trending: World's most haunted island up for auction

    Thursday, April 17 2014 12:17 PM EDT2014-04-17 16:17:05 GMT
    Poveglia. Image Wikimedia CommonsPoveglia. Image Wikimedia Commons
     A small "haunted" island off the coast of Italy near Venice will hit the auction block in May.
    A small "haunted" island off the coast of Italy near Venice will hit the auction block in May.
Powered by WorldNow

200 South Parker Street, Tampa, FL 33606

Telephone: 813.228.8888
Fax: 813.225.2770
Email: news@wfla.com

Can’t find something?
Powered by WorldNow
All content © Copyright 2000 - 2014 Media General Communications Holdings, LLC. A Media General Company.