Skip to main content

CTB-Locker ransomware encrypts WordPress sites and holds them hostage

hacking, computing
CreativeCommons
A fresh strain of ransomware called CTB-Locker has popped up online, and it encrypts WordPress websites rather than users’ computers. So far more than 100 sites have been affected.

The ransomware, also known as Critroni, operates more or less in the same way as traditional ransomware when it encrypts a user’s files and demands fee in bitcoin to decrypt and return the data. In the case of CTB-Locker, which is a PHP program, it instead targets a website.

The culprit will usually hack a website that is poorly secured and replace its index.php or index.html files with different files that encrypt the site’s data with AES-256 encryption, and will also display a warning message on the homepage demanding money along with instructions on how to buy bitcoin.

“Decryption key is stored on a secret Internet server and nobody can decrypt your files until you pay and obtain the decryption key,” says the message. It demands .4 bitcoin to return the website to working order.

ctb-locker
Image used with permission by copyright holder

This latest iteration of ransomware was discovered by BleepingComputer’s Lawrence Abrams. He found that the CTB-Locker even comes with a live chat function, so you can actually message the hacker about paying the ransom, and this version of the ransomware has been signed with stolen certificates.

Abrams points out in his report that, as per usual, the only way to restore your files other than paying up is to use a back-up.

It appears that there are about a hundred sites infected with CTB-Locker. A Pastebin document has been created that lists many of the sites that appear to have been compromised. No major, big name sites are included.

If you’re a website owner who is concerned about this, you should check to make sure that you’re using the latest version of WordPress. Most of the sites targeted so far were poorly managed and used outdated versions or had installed vulnerable plug-ins.

CTB-Locker looks like a pretty specialized experiment from the author and it may not be a massive threat in the near future. However, it is the latest mutation of ransomware. We’ve seen several cases of infections coming up over the last few weeks with businesses and organizations like hospitals and school districts getting infected and paying the ransom.

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
Best Apple deals: Save on AirPods, Apple Watch, iPad, MacBook
Apple MacBook Air M1 open, on a table.

Apple has been a big player in the tech space for a long time, and it has pioneered some of the technology we use today, such as best wireless earbuds and the best smartwatches. If that wasn't enough, it even makes some of the best best laptops and best tablets on the market, so pretty much whatever tech you're looking for, Apple has an excellent version of it. Not only that, but Apple's ecosystem is also easily one of the best available, with only Samsung really competing in that space, and if you're already in the Apple ecosystem, then it makes sense to continue buying stuff from Apple.

Of course, Apple tech can be quite pricey, which is why we've gone out and searched through various big retailers to find you some of the best deals we can find. That includes everything from the MacBook to the AirTag, so hopefully, you can find the perfect deal that fits your needs and budget.
Apple AirTag (4-Pack) -- $80, was $99

Read more
Wholesale laptop deals: How to buy cheap computers in bulk
Three Asus laptops set up on a counter.

If you need to furnished an entire office or classroom with laptops, monitors, or workstations, regular laptop deals from the major retailers just aren't going to cut it. You need extensive discounts on hardworking machines. Thankfully all of the major laptop brands have outlet sites focused specifically on major price cuts and refurbished products. Here are the best online options for wholesale laptop deals.
Wholesale laptops deals from Lenovo Outlet

Lenovo Outlet is a special section of Lenovo's site that focuses on cheap new and refurbished laptops. There are a lot of Lenovo laptop deals, including Lenovo's Notebook, IdeaPad and even the powerful ThinkPad line. All of the renewed laptops have been Certified Refurbished, meaning Lenovo themselves gave the laptops a once-over and decided they're good as new. If you think you'll be a repeat customer, you can sign up for , which gets you access to Lenovo's private business site, which has exclusive deals on bundles.

Read more
How to change your Yahoo password on desktop and mobile
A Yahoo mail inbox.

One of the best ways to keep your many email inboxes safe and secure is by frequently changing your password. While this may sound inconsequential, periodic login updates end up being one of the biggest deterrents against hackers and other malcontents. If Yahoo is your email platform of choice, we’ve put together this guide to teach you how to update your account password in just a few simple steps.

Read more