1 min read

On the Cryptolocker Takedown #fail

Răzvan STOICA

December 06, 2013

Ad One product to protect all your devices, without slowing them down.
Free 90-day trial
On the Cryptolocker Takedown #fail

Bitdefender researchers have identified a number of domains which are still hosting Cryptolocker malware command and control servers, after the takedown attempt by a group of cyber-vigilantes earlier this week.

All of the still active domain names are algorithmically generated, but somehow the cyber-vigilantes failed to take them into account, so the Cryptolocker network is still under full control of its creators. Some domains which were hard-coded into the Cryptolocker virus itself were not included in the takedown, but there seem to be no active command and control servers there at this time.

In any event, successfully sinkholing the entire Cryptolocker network and leaving it at that would create about as many problems as it solves. A takedown attempt must be combined with with some way to retrieve the private keys already present on command and control servers. Otherwise, many victims would be left with absolutely no way to decrypt files already encrypted by Cryptolocker.

tags


Author



Right now

Top posts

LuminousMoth – PlugX, File Exfiltration and Persistence Revisited

LuminousMoth – PlugX, File Exfiltration and Persistence Revisited

July 21, 2021

9 min read
How We Tracked a Threat Group Running an Active Cryptojacking Campaign

How We Tracked a Threat Group Running an Active Cryptojacking Campaign

July 14, 2021

10 min read
A Note from the Bitdefender Labs Team on Ransomware and Decryptors

A Note from the Bitdefender Labs Team on Ransomware and Decryptors

May 26, 2021

2 min read
New Nebulae Backdoor Linked with the NAIKON Group

New Nebulae Backdoor Linked with the NAIKON Group

April 28, 2021

1 min read
Good riddance, GandCrab! We’re still fixing the mess you left behind.

Good riddance, GandCrab! We’re still fixing the mess you left behind.

June 17, 2019

5 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Golang Bot Starts Targeting WordPress Websites Golang Bot Starts Targeting WordPress Websites
Silvia PRIPOAESilviu STAHIE
3 min read
Darkside Ransomware Decryption Tool Darkside Ransomware Decryption Tool
Bitdefender

January 11, 2021

2 min read
Towards a Universal Security Solution against Bluetooth Low Energy Attacks Towards a Universal Security Solution against Bluetooth Low Energy Attacks
Bitdefender

July 13, 2020

1 min read