CryTekk Ransomware
First observed in January 2019, CryTekk is a new variant of the HiddenTear ransomware. CryTekk differs from other HiddenTear variants in that the ransom note directs users to a phishing site designed to capture credit card details and personal information.
Summary
First observed in January 2019, CryTekk is a new variant of the HiddenTear ransomware. CryTekk differs from other HiddenTear variants in that the ransom note directs users to a phishing site designed to capture credit card details and personal information.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication there is little information available on the method used to deliver the ransomware. However, there are indications it is delivered by spam email campaigns.
CryTekk encrypts files using an AES-256 cipher, before appending them with the “.locked” extension. It attempts to remove Volume Shadow Copies and system restore points before deploying a ransom note named ‘README.html’ to the desktop. Where possible it will attempt to detect the default system web browser and use it to display the ransom note on screen.
The ransom note offers users with two payment options, pay from a cryptocurrency account or PayPal via a "Buy Now" button. Clicking the "Buy Now" button opens a browser tab to a series of phishing pages asking for credit card details and personal information.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
Open source tools are available which claim to be able to decrypt files encrypted by HiddenTear ransomware and it's variants. However, these tools are not tested by NHS Digital and we cannot guarantee their effectiveness at resolving the problem. Users wishing to use one of these tools do so at their own risk. |
Last edited: 14 February 2020 2:53 pm