Cr1ptT0r Ransomware
First observed in November 2018, Cr1ptT0r is a ransomware tool available on a number of dark web hacking forums.
Summary
First observed in November 2018, Cr1ptT0r is a ransomware tool available on a number of dark web hacking forums.
Threat details
Cr1ptT0r is delivered as an ELF file to vulnerable devices using a number of known exploits.
Once it has gained access, Cr1ptT0r will encrypt all files with the curve25519xsalsa20poly1305 algorithm from the Sodium cryptographic library. It does not append the encrypted files with a new extension but instead adds the end-of-file marker, "Cr1ptT0r", along with the public key to each file.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:53 pm