2015 closed as the worst year for cybersecurity, and 2016 is expected to be even worse. Two important factors contribute to the current situation: the first is the evolution of ransomware, from the classic "police virus" to the ruthless cryptolocker. The second factor is certainly linked to the success of Bitcoin, a virtual currency based on a mathematical algorithm that is widespread on the dark web, due to the extreme difficulty (we could say impossibility) of tracking its exchanges. The extreme ease of creating a ransomware that encrypts the files of an infected PC, combined with the security of receiving a payment without being traced and arrested, has caused the phenomenon to explode.
Ransomware are not viruses, but very simple malware that make the device or the files contained within it inaccessible. They do not even need to mask their presence from the user, and they exploit the user's naivety for their spread. This is precisely why antivirus programs are struggling.
Cryptolocker, like the more archaic "police virus," is "caught" by clicking on an attachment in an email, which is usually a fake PDF file. This type of infection is historic and has existed since the dawn of time, exploiting on one hand the naivety of users and on the other the fact that Windows hides known file extensions by default. Therefore, by naming a file with a double extension, for example: procedura_conferma_bonifico.PDF.exe and setting the program icon to that of a classic PDF document, most inattentive users will mistake the program for a harmless PDF document. It is true that Windows will display a series of installation confirmation windows, but since these are seen by users as nuisances, they will not pay attention, clicking bored and annoyed on "OK" to any question that the operating system and the ransomware installer may ask.
In a sense, it is as if people are used to giving their house keys to various acquaintances and absentmindedly handing them to the first stranger who asks. There is no security system capable of protecting a user from themselves.
How to defend against Cryptolocker?
First of all, it is important to be cautious with any attachments in emails and files downloaded from the Internet, even when the received email seems to be sent from a contact of yours. This is because the email could be sent from an infected PC without the user's knowledge or could even be simply fake. I have encountered users who got infected by a fake email that appeared to be sent from INPS.
Reading the email carefully is the first step; many are barbarically translated into Italian with Google Translator, so always be wary of: “poste italiene informa che tu avere inviato bonifico 500 euro, premere per operazione anullare qui” which is definitely a Russian or Chinese cybercriminal. Unfortunately, thanks to Bitcoin transactions, ransomware from Italian cybercriminals are circulating, so in impeccable Italian. What previously stopped local criminals was the fact that by following the money, law enforcement would eventually catch them.
Keep your important data safe by making regular backups on an external drive, but remember that cryptolocker and its variants can also encrypt and thus render unusable the files on external drives connected to the PC, so once the backup is done, the drive should be disconnected. Documents saved on a cloud service like Dropbox and similar (excluding subscription versions with file history) are not safe in case one accidentally installs one of the circulating cryptolocker variants. There are no issues with home systems; any backups made on DVD and Blu-ray, once burned, are accessible in read-only mode. At the corporate level, the best solution is always to consult a professional.
What to do if infected by Cryptolocker?
Immediately turn off the infected PC, preventing cryptolocker from completing the encryption of all files on your PC and on external devices and shared network drives. You will then need to access the disks of the infected PC from another system to recover the files that have not yet been encrypted by the ransomware. I recommend having this operation done by a professional who will also restore the PC.
Do not pay the ransom, you have no guarantee of receiving the key to decrypt the files; it may have been lost by the same cybercriminal, and sending it to you still exposes them to further risk, as once the money is collected, no one forces them to comply.
To recover files encrypted by cryptolocker? The chances of recovering encrypted files are close to zero (since 2016, the chances of recovery have increased), especially with the latest versions of cryptolocker. Unfortunately, the algorithm used by Cryptolocker is based on 256-bit Aes encryption, which is particularly robust, and therefore the probability of being able to decrypt the files without having the appropriate keys is quite remote. For older versions, cybersecurity experts from Fireeye and Fox-IT have managed to recover the decryption keys and made them available for free. There are various online services based on DecryptCryptolocker that allow you to use this service; just send a file (choose one without personal information) to receive the necessary material via email. In most cases, it will not be possible to recover them as there are different variants of the ransomware, and new ones are created every day, among the most widespread: PrisonLocker, CryptoDefense, TorLocker, and CryptoBit. While they operate similarly to Cryptolocker, they use different cryptographic keys.
To recover the data, we have two options:
- Try using Kaspersky Ransomware Decryptor https://noransom.kaspersky.com to decrypt some encrypted files; if the version that infected us is not very recent, we have some chance of success.
- If it is not possible, the only alternative is to resort to a professional service; in that case, I recommend iRecovery (https://www.irecoverydata.com). They will ask you to send the HD and various media to their headquarters, and after an analysis (shipping and analysis are free), they will provide a quote, and it will be up to you to decide whether to attempt to recover the files or not.