Skip to main content

CTB-Locker ransomware encrypts WordPress sites and holds them hostage

hacking, computing
CreativeCommons
A fresh strain of ransomware called CTB-Locker has popped up online, and it encrypts WordPress websites rather than users’ computers. So far more than 100 sites have been affected.

The ransomware, also known as Critroni, operates more or less in the same way as traditional ransomware when it encrypts a user’s files and demands fee in bitcoin to decrypt and return the data. In the case of CTB-Locker, which is a PHP program, it instead targets a website.

The culprit will usually hack a website that is poorly secured and replace its index.php or index.html files with different files that encrypt the site’s data with AES-256 encryption, and will also display a warning message on the homepage demanding money along with instructions on how to buy bitcoin.

“Decryption key is stored on a secret Internet server and nobody can decrypt your files until you pay and obtain the decryption key,” says the message. It demands .4 bitcoin to return the website to working order.

ctb-locker
Image used with permission by copyright holder

This latest iteration of ransomware was discovered by BleepingComputer’s Lawrence Abrams. He found that the CTB-Locker even comes with a live chat function, so you can actually message the hacker about paying the ransom, and this version of the ransomware has been signed with stolen certificates.

Abrams points out in his report that, as per usual, the only way to restore your files other than paying up is to use a back-up.

It appears that there are about a hundred sites infected with CTB-Locker. A Pastebin document has been created that lists many of the sites that appear to have been compromised. No major, big name sites are included.

If you’re a website owner who is concerned about this, you should check to make sure that you’re using the latest version of WordPress. Most of the sites targeted so far were poorly managed and used outdated versions or had installed vulnerable plug-ins.

CTB-Locker looks like a pretty specialized experiment from the author and it may not be a massive threat in the near future. However, it is the latest mutation of ransomware. We’ve seen several cases of infections coming up over the last few weeks with businesses and organizations like hospitals and school districts getting infected and paying the ransom.

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
The best all-in-one printers you can buy in 2024
Canon's imageClass MF753Cdw has a quick, full-duplex ADF.

If you're shopping for the best printers for a home office, an all-in-one is a good choice. Multifunction printers include scanners to digitize receipts, invoices, and other documents. The scan and print functions combine to make copies. Some all-in-one printers can connect to a phone line to act like a fax machine.

Multifunction printers are like the smaller cousins of the bulkier copiers you might see at the office. As our printer buyers' guide points out, an all-in-one printer usually costs less than it would to buy a printer and scanner separately. Here are some of the best multifunction printers on the market today.

Read more
Asus pits AMD’s performance against Intel’s efficiency
Asus ProArt PX13 front view showing display and keyboard.

Several new laptops chipsets have been introduced lately in response to Microsoft's Copilot+ PC AI initiative. They sport faster neural processing units (NPUs) to speed up on-device AI processing and make it more efficient, but they're not precisely the same. AMD's Ryzen AI 9 chipsets are aimed at overall performance, while Intel's Lunar Lake is aimed at efficiency.

The Asus ProArt PX13 is one of the first with AMD's chipset, and it's a highly portable 13-inch laptop. The Asus Zenbook S 14 is aimed at great battery life in a thin-and-light design using Lunar Lake. Both are some of the best laptops you can buy today, but which laptop is the better choice?
Specs and configurations

Read more
Nvidia might finally fix its VRAM problem — but it will take time
The Razer Blade 14 and 18 on a table.

It's no secret that some of Nvidia's best graphics cards could use a little more VRAM. According to a new leak, Nvidia may be addressing that problem in a big way -- at least in laptops. The RTX 5090 laptop GPU is now reported to come with 24GB VRAM across a 256-bit memory bus. The downside? These new laptops might not make it to market as soon as we'd hoped.

The information comes from Moore's Law Is Dead, who cites his own industry sources as he spills the beans on RTX 50-series laptop specs. Up until now, we've not heard much about Nvidia's plans for RTX 50 laptops, indicating that they might be a few months away. The YouTuber agrees with this, saying that Nvidia might be targeting a launch window in the first or second quarter of 2025. This might not affect the entire lineup, though.

Read more