RansomWare increasing

In last few years, we saw an innumerable rise in ransomware threats ranging from Cryptowall to Locky ransomware discovered last week.

Now, another genre of ransomware had been branched out from the family of CTB-Locker Ransomware with an update to infect “Websites”, according to Lawrence Abrams of Bleeping Computer.

The newly transformed ransomware dubbed “CTB-Locker for Websites” exclusively hijacks the websites by locking out its data, which would only be decrypted after making a payment of 0.4 Bitcoins.

A new malicious program that encrypts files on Web servers has affected at least 100 websites over the past few weeks, signaling a new trend in ransomware development.

The program, which is written in PHP, is called CTB-Locker, a name also used by one of the most widespread ransomware programs for Windows computers. It’s not clear though if there’s a relationship between this new Web-based ransomware and the Windows version.

A new malicious program that encrypts files on Web servers has affected at least 100 websites over the past few weeks, signaling a new trend in ransomware development.

The program, which is written in PHP, is called CTB-Locker, a name also used by one of the most widespread ransomware programs for Windows computers. It’s not clear though if there’s a relationship between this new Web-based ransomware and the Windows version.

Once installed on a Web server, the program replaces the site’s index.php and creates a directory called Crypt that contains additional PHP files. It starts to encrypt all the files in the server’s Web directory when it receives a specifically crafted request from an attacker.

After the encryption process is complete, the website’s home page will display a message asking for a payment to be made in bitcoin.

One of the first attacks with this Web-based version of CTB-Locker was reported on Feb. 12 when the website of the British Association for Counselling and Psychotherapy fell victim to it.

It wasn’t immediately clear at the time whether the website was affected by a real ransomware attack or if it was just an attempt to scare the website owners. Some people were understandably skeptical because the CTB-Locker name had previously only been associated with Windows ransomware.

Researchers from Stormshield, a subsidiary of Airbus Defence and Space, have since managed to obtain a full copy of the malicious code from another affected website. In fact they they found 102 websites that have been infected with this Web-based ransomware so far.

Advertisements
This entry was posted in Uncategorized and tagged , , , , . Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s