Skip to content
EntityQ15122248· pop 22· linked from 247 articles

CryptoLocker

Sign in to save

The CryptoLocker ransomware attack was a cyberattack using the CryptoLocker ransomware that occurred from 5 September 2013 to late May 2014. The attack utilized a trojan that targeted computers running on Microsoft Windows, and was believed to have first been posted to the Internet on 5 September 2013. It propagated via infected email attachments, and via an existing Gameover ZeuS botnet. When activated, the malware encrypted certain types of files stored on local and mounted network drives using RSA public-key cryptography, with the private key stored only on the malware's control servers. Th

Key facts

Computer virus.classification
Trojan horse
Computer virus.type
Ransomware
Computer virus.subtype
Cryptovirus
Computer virus.isolation_date
2 June 2014
Computer virus.platform
Windows

via Wikipedia infobox

Wikidata facts

Show 2 more facts
anti-virus alias
TROJ_CRILOCK.DW
inception
2013-09-05
Sources (2)

via Wikidata · CC0

~9 min read

Article

7 sections
Contents
  • Operation
  • Takedown and recovery of files
  • Mitigation
  • Money paid
  • Clones
  • See also
  • References

The CryptoLocker ransomware attack was a cyberattack using the CryptoLocker ransomware that occurred from 5 September 2013 to late May 2014. The attack utilized a trojan that targeted computers running on Microsoft Windows, and was believed to have first been posted to the Internet on 5 September 2013. It propagated via infected email attachments, and via an existing Gameover ZeuS botnet. When activated, the malware encrypted certain types of files stored on local and mounted network drives using RSA public-key cryptography, with the private key stored only on the malware's control servers. The malware then displayed a message which offered to decrypt the data if a payment (through either bitcoin or a pre-paid cash voucher) was made by a stated deadline, and it threatened to delete the private key if the deadline passes. If the deadline was not met, the malware offered to decrypt data via an online service provided by the malware's operators, for a significantly higher price in bitcoin. There was no guarantee that payment would release the encrypted content.

Although CryptoLocker itself was easily removed, the affected files remained encrypted in a way which researchers considered unfeasible to break. Many said that the ransom should not be paid, but did not offer any way to recover files; others said that paying the ransom was the only way to recover files that had not been backed up. Some victims claimed that paying the ransom did not always lead to the files being decrypted.

Connections

Categories