Skip to main content

After update, Kaspersky tool no longer combats CryptXXX ransomware

Ransomware is a growing threat to anyone that uses a computer — even the U.S. House of Representatives has been a recent target. This kind of attack can result in a desperate situation for the victim, and there’s now word that a common strain of the malware has been upgraded to resist countermeasures.

Last month, Kaspersky released a tool intended to help users targeted by the CryptXXX ransomware regain access to their systems without paying a bounty to the culprits. Now, researchers at Proof Point have identified a new version of the malware that can sidestep the company’s RannohDecrypter utility.

Recommended Videos

RannohDecrypter was originally developed to help users targeted by the Rannoh Trojan, but was later expanded to tackle CryptXXX as well. In response to this, the authors of CryptXXX have made some adjustments to the way their weapon targets systems to extort their owners.

Please enable Javascript to view this content

Version 2.006 of CryptXXX locks down the targeted system completely, which was initially interpreted by Proof Point as a “quick and dirty” means of preventing the use of RannohDecrypter. However, there’s another more sophisticated strategy at play that removes Kaspersky’s tool from the equation.

CryptXXX now causes an error message to read, “encrypted file size does not equal to original” when the user attempts to employ RannohDecrypter. It’s thought that the malware is using the zlib data compression library as a means of counteracting the utility.

This development illustrates the cat-and-mouse game of modern security research. Research teams and malware developers are continually trying to stay one step ahead of the competition, which often boils down to studying the last move made by their opponent.

The advice on how to stay safe remains the same; keep your security software up to date, and avoid clicking any suspicious links, or opening unsolicited email attachments.

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Need a budget-friendly laptop? Get this Asus deal at Walmart
The Asus VivoBook 15 laptop open on a white background.

You don't need to spend over a thousand dollars to end up with a dependable device from laptop deals -- you just need to be patient in waiting for a budget-friendly offer that will still provide reliable performance. Here's one: the Asus Vivobook 15 for only $299 from Walmart, following a $100 discount on its original price of $399. We're not sure when it will go back to its regular price though, so we highly recommend finishing your purchase quickly as that could happen at any moment.

Why you should buy the Asus Vivobook 15 laptop
Let's get this out of the way -- at its affordable price, you can't expect the Asus Vivobook 15 to match the performance of the best laptops. The device, however, will prove to be a trustworthy daily companion for regular tasks such as doing online research and typing documents, as well as watching some streaming shows when you're taking a break. It runs on the 12th-generation Intel Core i5 processor, Intel UHD Graphics, and 8GB of RAM, which will be more than enough for these activities. The laptop also ships with a 256GB SSD for ample storage space for your files, and it's got Windows 11 Home pre-installed.

Read more
Apple CEO should do a Steve Jobs on Siri delay, analyst says
Invoking Siri on iPhone.

Apple CEO Tim Cook should go public to explain the delay in integrating advanced Siri capabilities across its ecosystem, rather than Apple releasing the news quietly via a tech site last week, according to prominent Apple analyst Ming-Chi Kuo.

The tech giant showcased an AI-powered Siri at its WWDC event in 2024, as part of its Apple Intelligence initiative. While the virtual assistant does now have some AI smarts, the more advanced features -- including personalized responses, task completion across multiple apps, and on-screen awareness --have been delayed until next year at the earliest.

Read more
Nvidia claims RTX 5000 shipped better than 4000 but gamers are still waiting
The RTX 5090 sitting on a pink background.

Nvidia is trying to make its GeForce RTX 5000 series seem more impressive to the media by suggesting that the latest GPUs are selling better than the previous generation. However, many pundits aren’t buying the claim.

PC Mag pondered whether Nvidia has orchestrated a “paper launch” of the RTX 5000 series, suggesting that there might not be much of a product available for consumers. The majority of the people with their hands on the GPUs, especially the high-end models such as the 5090 and 5080 appear to be reviewers, influencers, and other determined enthusiasts as opposed to everyday gamers, who are still using prior generation GPUs at higher rates.

Read more