On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

October 27th, 2009

New LoroBot ransomware encrypts files, demands $100 for decryption

Posted by Dancho Danchev @ 4:52 pm

Categories: Anti Virus, Botnets, Browsers, Hackers, Malware, Passwords, Spyware and Adware, Viruses and Worms

Tags: Decryption, SMS, Text Messaging/SMS/MMS, Telephony, Online Communications, Networking, Dancho Danchev

Researchers from CA have intercepted a new ransomware variant encrypting popular file extensions (.zip; .rar; .pdf; .rtf; .txt; .jpg; .jpeg; .waw; .mp3; .db; .xls; .docx; .xlsx; .doc) and demanding a $100 for the decryption software.

According to the message which replaces the desktop’s background upon execution, the files are encrypted with 256-bit AES encryption, and that “there’s a 0% chance that you will be able to manually decrypt the files without the encryption key“. However, this particular cybercriminal appears to be bluffing since the ransomware encrypts the data using the XOR cipher.

Naturally, by doing so he allowed CA’s researchers to release a free decryptor for Win32/Gpcode.J. Despite that compared to previous campaigns, this one looks rather primitive, ransomware is clearly a trend, one that has already started converging with popular delivery channels such as scareware, and utilizing efficient payment processes such as the ubiquitous SMS micro-payment.

Throughout the entire 2009, cybercriminals have indicated their long-term interest in the development of alternative extortion tactics in order to efficiently earn as much micro-payment revenue as possible. The most recent case of such an alternative extortion tactic, was the introduction of SMS ransomware variant that was displaying persistent inline ads within the browsers of infected victims, often showing disturbing adult content, while requiring a premium-rate SMS for removal.

With the ever-decreasing price for do-it-yourself SMS ransomware building tools within the underground marketplace (average price is between $15 and $30), new market entrants will inevitably prompt the vendors of these releases to “innovate” and introduce new features in an attempt to compete with one another.

Interestingly, despite GPCode’s and LoroBot’s practice of encrypting popular file extensions, the majority of SMS-based ransomware releases currently offered for sale, emphasize on the practice of locking down an infected party’s computer using “Unlicensed copy of Windows” themes, instead of encrypting files.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 68 Talkback(s)
wow that's reallly harsh...
:"You are as credible as an Apple ad. "

happy happy

... (Read the rest)
Posted by: gabriel bear Posted on: 12/02/09 You are currently: a Guest | | Terms of Use
You forgot to mention..  AzuMao | 10/27/09
Use the same rule as in political reporting  frgough | 10/28/09
Really?  rob.sharp@... | 10/28/09
Yeah, right  cdmsr | 10/28/09
Really?  nordyj2001@... | 10/28/09
You missed his point  NBrazil | 10/28/09
This is ZDNET not Fox news  gtaylor2 | 10/29/09
a men to that  anonymous99 | 10/30/09
If Java Applet? it's isolated from OS! Use Linux! wink  i2fun@... | 11/04/09
Look at the bigger size version of the screenshot, it's all in there  The Mentalist | 10/28/09
But my UAC nanny screen will protect you!!  Wintel BSOD | 10/28/09
The Russian Characters  eric.d.dobbs@... | 10/28/09
RE: New LoroBot ransomware encrypts files, demands $100 for decryption  Loverock Davidson | 10/28/09
So the only platform that can be hit by malware is the safest platform...  The Mentalist | 10/28/09
wrong as usual  pgit | 10/28/09
I'm right  Loverock Davidson | 10/28/09
How is a Win32 API...  Stuka | 10/28/09
You're wrong  leiko84 | 10/28/09
Meant for Loverock Davidson  leiko84 | 10/28/09
He's just here to troll  Wintel BSOD | 10/28/09
awright then..  pgit | 10/28/09
I have to agree  skeptic tank | 10/28/09
Too Flippin' Right  murphym@... | 10/29/09
Yet another ignorant M$ Windows user!!!  leiko84 | 10/28/09
Enough Babble about what O/S is best already  mstarks67 | 10/28/09
watch out...  g-ssg | 10/28/09
Safe  dev-null | 10/28/09
Thank you dev-null  leiko84 | 10/28/09
Never said which O/S is the best!!!!!!!!  leiko84 | 10/28/09
Relax  mstarks67 | 10/28/09
It's ok!  leiko84 | 10/28/09
Oh, geez  nordyj2001@... | 10/28/09
OMG!!!!!!!!!!!!!!  leiko84 | 10/29/09
Word up!  Adimo | 10/30/09
Macs are also...  arminw | 12/01/09
Linux is 100% safe...?  Tommy S. | 10/29/09
OMG!!!!!!!!!!!!!!!!  leiko84 | 10/29/09
Do me a favor...  leiko84 | 10/29/09
And BTW...  leiko84 | 10/29/09
You're ...  ryans565 | 10/29/09
wow that's reallly harsh...  gabriel bear | 12/02/09
Valueless business meets "activation" mechanics  cquirke | 10/28/09
I believe someone already named it "******* Genuine Advantage"  The Mentalist | 10/28/09
Sounds like you are describing Wall Street ...  kd5auq | 10/28/09
This current trend is only the tip of the iceberg.  jay_kuykendall@... | 10/28/09
Activation  dev-null | 10/28/09
Valid comparison  rahbm | 10/28/09
If Microsoft's activation...  arminw | 12/01/09
RE: New LoroBot ransomware encrypts files, demands $100 for decryption  vbnomad@... | 10/28/09
Do the perpetrators of this kind of crime ever get caught or prosecuted?  timmycb | 10/28/09
Send them to Los Angeles and Google, via e-mail  HypnoToad72 | 10/28/09
vaguely related  Jack-Booted EULA | 10/28/09
not really related in a way...  loki71 | 10/28/09
RE: New LoroBot ransomware encrypts files, demands $100 for decryption  DragonAX | 10/28/09
Find 'em...  Rodo1 | 10/28/09
RE: Find 'em  bfilipiak@... | 12/01/09
RE: New LoroBot ransomware encrypts files, demands $100 for decryption  sail4evr | 10/28/09
RE: New LoroBot ransomware encrypts files, demands $100 for decryption  Bilmekanikeren | 10/28/09
RE: New LoroBot ransomware encrypts files, demands $100 for decryption  JohnMayer | 10/29/09
What is wrong with you fools?  archangel9999 | 11/02/09
I meant to put this comment here...  www_bug | 11/10/09
So did I ...  dippleydokus | 12/01/09
r4  rickyvogay | 11/07/09
 www_bug | 11/10/09
RE: New LoroBot ransomware encrypts files, demands $100 for decryption  goingbust | 12/01/09
RE: New LoroBot ransomware encrypts files, demands $100 for decryption  dippleydokus | 12/01/09
create a full system image every 2 weeks  pcguy777 | 12/01/09
full system image every 2 weeks...  jpdemers@... | 12/01/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here