跳到主体内容

Saving Private Files: what extortionists demand for decrypting user data

2015年3月12日

Computer users in many countries are increasingly falling victim to so-called encryption malware – programs that encrypt important data on infected computers and then demand a ransom to decrypt it.

Computer users in many countries are increasingly falling victim to so-called encryption malware – programs that encrypt important data on infected computers and then demand a ransom to decrypt it. In 2014, over 7 million attempts to carry out such attacks were made against Kaspersky Lab users alone. Kaspersky Lab experts have prepared an overview of the evolution of encryption malware, as well as advice on how to avoid being affected by this threat.

Encryption malware gets special attention because cybercriminals are continually changing the tools they use, including cryptographic schemes, code obfuscation techniques, executable file formats, and infection vectors. This type of malware is usually distributed via spam or attacks against remote administration systems. The persistence of this form of extortion is easily explained: unlike banking Trojans, which generate an ‘income’ only if the victim uses online banking, a piece of encryption malware, having once infected a computer, will always find something to encrypt and hold to ransom.

Cybercriminals prefer to be paid in the Bitcoin cryptocurrency, which offers them a sufficiently high level of anonymity. At the same time, it is common for attackers to specify their rates in real-world currencies, such as US dollars, euros or rubles. The cost of decrypting data for home users starts at 1000 rubles (about $15) but can be as high as several hundred dollars. If a corporate computer is infected, the attackers’ demands increase five-fold. Cybercriminals are known to have demanded ransoms as high as 5000 euros to decrypt files. Sadly, companies that have lost their data often prefer to pay up rather than lose important information. It comes as no surprise, therefore, that businesses are a prime target for cybercriminals who use encryption malware to make money.

“If files have been successfully encrypted and there is no backup copy, the user has little chance of getting their data back. It would take a mistake by the attacker in terms of the design or implementation of the encryption scheme for a user to be able to decrypt the files - and this rarely happens now. This is why it is important to regularly back up important data and store the backup copies separately from the computer system. We also recommend using the latest versions of security solutions for protection. The System Watcher module included in all our current products not only scans the processes launched in the system and identifies any malicious activity, but also backs up user files if a suspicious program attempts to access them. If the analysis of a program indicates it is malicious, user data is automatically recovered,” commented Artem Semenchenko, malware analyst at Kaspersky Lab.

The full version of the paper on encryption malware and its characteristics can be found on Securelist.

Saving Private Files: what extortionists demand for decrypting user data

Computer users in many countries are increasingly falling victim to so-called encryption malware – programs that encrypt important data on infected computers and then demand a ransom to decrypt it.
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻