Skip to main content

Hackers are playing Crysis on remote business computers, and it’s not a fun game

A hacker inputting code into a system.
Image used with permission by copyright holder
At one time there was ongoing joke in the gaming industry about whether a PC can run Crysis, a first-person shooter from Crytek that was essentially ahead of its time. After its launch in 2007, the game was unplayable on high-end hardware when set at its high resolutions and settings, thus the game became a benchmark for years. Since then, technology has caught up, and now the “Crysis” name has resurfaced in the form of ransomware that is now attacking businesses in Australia and New Zealand.

Although Crysis originally surfaced back in February, these latest attacks were first discovered by Trend Micro in early August. It’s distributed through spam emails packed with a Trojan-based attachment or a link to a compromised website. It also lurks on websites that distribute fake installers for valid programs and applications sold through retail.

However, the security firm also discovered that the hackers behind the latest attacks are sneaking Crysis into business networks through the Remote Desktop feature built into the Windows platform. This service allows the user to remotely access another Windows machine as well as other local devices and resources like printers, the Clipboard, plug and play media, and more. A remote computer’s hard drive can even be shared (mapped), allowing other users to access the drive’s contents as if it’s installed in their machine.

According to Trend Micro, the hackers are grabbing Remote Desktop credentials by using brute force attacks, a method that employs software to continuously guess a password until the correct one is determined. Once hackers gain access to a remote computer, they use Crysis to encrypt the computer’s local files, forcing companies to shell out big bugs to regain access.

However, Trend Micro reports that Crysis can be used on an even larger scale. Once it encrypts the files on a remote computer, it has the ability to scan for mapped drives, removable drives, and other devices on the network, and infect those as well. Crysis could eventually migrate to the company’s file server and hold its contents hostage for even bigger bags of cash.

“Cleanup from Crysis has been noted to be tricky. In its attacks on Australian and New Zealand businesses, we saw this ransomware injecting Trojans to redirected and/or connected devices such as printers and routers,” the security firm reports. “This part of Crysis’ infection chain allows the attackers to regain access to and reinfect the system, even after the malware has been removed from the affected computer.”

That means if a business pays the hackers money to regain access to their files, those hackers can re-encrypt the files again. Trend Micro recommends that companies located in Australia and New Zealand should shut down access to Remote Desktop, or change the port that the Remote Desktop protocol (RDP) is currently using. Companies should also beef up Remote Desktop credentials and enforce two-step authentication, which requires a second form of identification on top of the Remote Desktop login credentials.

“Ensuring that connected devices are securely wiped during cleanups can mitigate the risks of further damage, while utilizing encryption channels can help foil attackers from snooping on remote connections,” the firm adds. “Keeping the RDP client and server software up-to-date can also prevent potential vulnerabilities in RDPs from being exploited.”

Naturally, Trend Micro has the perfect solution for keeping Crysis off a company’s network: its service for enterprises, and its service for small to medium-sized businesses.

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Dell’s XPS 13 for $599 deal is back, and who knows for how long
The Dell XPS 13 in front of a window.

Dell almost always has great laptop deals and for a little while now, it’s been selling an older model of the Dell XPS 13 for just $599. That deal continues today but we’re really not sure how long it’s going to stick around for. It feels like it must be ending very soon. The laptop usually costs $799 so you’re saving $200 but overall, this is a fantastic deal for the hardware involved. If you’re keen to learn more before the deal ends, keep reading.

Why you should buy the Dell XPS 13
Dell is one of the best laptop brands out there so you simply can’t go wrong with purchasing from it. With this model, you get a 12th-generation Intel Core i5-1230U processor along with 8GB of memory and 256GB of SSD storage. There’s also a 13.4-inch full HD+ screen with 1920 x 1200 resolution, 500 nits of brightness, and anti-glare properties. That’s fairly standard stuff at this price but it’s the build quality of the Dell XPS 13 which makes it stand out so much.

Read more
M4 vs. M3: How much better are Apple’s latest chips?
An official rendering of the Apple M4 chip.

Apple has announced the M4 chip, its successor to the M3 that’s currently found in a bunch of Macs and iPads. The M3 is an excellent chip and a real leap above the M2 that came before it, so the question is whether the M4 can manage a similar feat.

Right now, the M4 is only in the iPad Pro, and that means information about how good it is and what it does is rather limited. But if you’re interested in finding out more, you’re in luck, as we’ve gathered up everything we know about Apple’s M4 chip and compared it side by side with the M3. If you want to learn more about Apple’s next chip -- and how it compares to the M3 -- read on.
Where can you find these chips?

Read more
iMac deals: New, renewed and refurbished iMac computers
Apple iMac with Retina 5K Display review close

If you're in the Apple ecosystem and need a desktop computer rather than something like a MacBook, then you'll want to go for the Apple iMac, which is one of the best all-in-one computers on the market. There are quite a few screen sizes and specs to pick from, and if you're willing to go for a renewed option, you can get some older yet still powerful iMacs for a great price with desktop deals. Even if you aren't, there are still some great Apple deals you can take advantage of to save yourself some money, which is why we went out and scoured the internet for the best deals we could find. If you need something portable, check out MacBook deals. For extra savings, check out refurbished MacBook deals.
Apple 21.5-inch iMac (2018) Renewed -- $409, was $460

Even cheaper than any of the MacBook deals going on, this Apple 21.5-inch iMac (2018) might be a few years old but it offers plenty of juice for the price. That's the beauty behind many iMacs -- they last a long time thanks to offering reliable hardware and the benefits of MacOS, which tends to mean they stay fast for awhile. In the case of the 2018 21.5-inch iMac, you get a 2.7GHz Quad-Core Intel Core i5 processor paired up with 16GB of memory which is a great set of specs for ensuring you can get plenty of work done.

Read more