On TechRepublic: Why Android beats iPhone
BNET Business Network:
BNET
TechRepublic
ZDNet

August 13th, 2008

New Gpcode (encryption) ransomware speading via botnet

Posted by Ryan Naraine @ 9:19 am

Categories: Botnets, Browsers, Complex Attacks, Data theft, Passwords, Spam and Phishing, Viruses and Worms

Tags: Encryption, File, Security, Ryan Naraine

Gpcode ransomware returns, again

There are confirmed reports on a new version of the Gpcode ransomware being spread via a botnet.

According to Vitaly Kamluk of Kaspersky Lab (my employer), the Trojan encrypts files on an infected machine (AES-256) and leaves a text file named crypted.txt with a ransom note demanding $10 to decrypt the files.  It also changes the desktop wallpaper with a skull/crossbones image that contains a URL, an ICQ number and an e-mail address to contact the author.

[ SEE: Blackmail ransomware returns with 1024-bit encryption key ]

Kamluk provided a Russian-to-English translation of the text in the crypted.txt file but notes that the encryption claims are unconfirmed at this time.

We’re are analyzing the encryption algorithm in search of ways to crack the encryption and restore files. In the meantime, if you’ve been attacked by this latest Gpcode variant, try we suggest that victims attempt to restore their files using the methods described here to restore your files. We already have confirmed reports from victims have reported that this method does partially restore encrypted files.

Earlier this year, a variant of the Gpcode ransomeware was using the RSA encryption algorithm(1024-bit key), making it impossible to crack without the author’s key.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 5 Talkback(s)
RE: New Gpcode (encryption) ransomware speading via botnet
If concerned about the increase in ransomware attacks I would suggest using a whitelisting based product that only allows good applications to write to your disks.

Whitelisting solutions are s... (Read the rest)
Posted by: Nigel Westerfeld Posted on: 08/18/08 You are currently: a Guest | | Terms of Use
It's a 15 minute problem at best  JGehrken | 08/13/08
And what would you like to bet...  James T. Kirk | 08/14/08
It'll help teach people to BACK UP their data  twaynesdomain | 08/14/08
Yeah, backups...  MV_z | 08/17/08
RE: New Gpcode (encryption) ransomware speading via botnet  Nigel Westerfeld | 08/18/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and