Skip to main content

Ransomware app leaves de-cryption key on victim’s PC

A depiction of a hacker behind a screen of code.
Glebstock/Shutterstock

If you’ve ever seen any TV shows like “World’s Wildest Police Videos,” then you know that not all criminals are detail-oriented masterminds. Apparently, there there’s a Ransomware program out there whose creator can be counted among that group as well.

Ransomware is a form of malware that essentially locks down a user’s files, forcing them to pay hundreds in cash in order to regain access to their data. One piece of Ransomware, dubbed CryptoDefense, not only encrypts a victim’s files, but also leaves the decryption key on the same PC as well, according to security firm Symantec.

CryptoDefense employs Microsoft’s cryptographic methods as well as Windows software in order to create the plain text key that encrypts the files, which is then sent to the malware handler’s server. However, once that key is sent to the attacker, it’s also stored on the infected machine.

“The malware author’s poor implementation of the cryptographic functionality has left their hostages with the key to their own escape,” Symantec said.

However, because it takes a bit of technical know-how in order to extract the de-cryption key, it’s unlikely that the average user hit by CryptoDefense would be able to break free of the malware’s shackles. Despite it’s one big flaw, Symantec asserts that CryptoDefense has earned its handlers a hefty sum of $34,000 in a single month.

What do you think? Sound off in the comments below.

Editors' Recommendations

Topics
Konrad Krawczyk
Former Digital Trends Contributor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
Ransomware victims are refusing to pay — but is it working?
A depiction of a hacked computer sitting in an office full of PCs.

A new report has highlighted how ransomware payments to hackers have begun to slow down, with victims continuously opting to not cave in to demands.

Coveware, a company that provides ransomware decryption services, revealed some interesting analytics relating to the state of ransomware during the second quarter of 2022.

Read more
This anti-hacker group helps you escape ransomware for free
A depiction of a hacked computer sitting in an office full of PCs.

This week marks the sixth anniversary of the No More Ransom project, an initiative aimed at helping ransomware victims.

Operating as an online platform to help anyone who’s experiencing trouble after their system has been infected by some form of ransomware, No More Ransom was formed as a joint venture between law enforcement (Europol and the Dutch National Police) alongside IT security firms (Kaspersky and McAfee).

Read more
Ransomware gangs are evolving in new and dangerous ways
Silhouette of male hand typing on laptop keyboard at night.

With digital technology growing at a rapid pace, ransomware gangs and their methods continue to advance at an aggressive rate as well.

This observation was detailed by cybersecurity and antivirus giant Kaspersky via a new report, highlighting fresh ransomware trends that have materialized throughout 2022.

Read more