Encryption goof fixed in TorrentLocker file-locking malware

A new variant of TorrentLocker fixes a problem that allowed encrypted files to be freed

The developers of a type of malicious software that encrypts a computer's files and demands a ransom have fixed an error security experts said allowed files to be recovered without paying.

The malware, called TorrentLocker, popped up last month, targeting users in Australia, according to iSight Partners, a security consultancy. It now appears to be also geo-targeting victims in the U.K.

TorrentLocker's developers ironically made a similar mistake as the creators of another ransomware program, CryptoDefense. Researchers found earlier this year that CryptoDefense left a decryption key on a person's computer, although the error was soon fixed.

Earlier this month, researchers with the consultancy Nixu found that TorrentLocker used the same keystream to encrypt all of a computer's files. That was a mistake, as a keystream should never be used more than once, according to a writeup on the SANS Institute blog.

"As the encryption was done by combining the keystream with the plaintext file using the XOR operation, we were able to recover the keystream used to encrypt those files by simply applying XOR between the encrypted file and the plaintext file," they wrote.

With the error out in the open, it was only a matter of time before it was fixed.

Richard Hummel, a senior technical analyst with iSight, wrote that a variant of TorrentLocker without that bug has now been found, which shows the "extremely high pace of innovation of our collective adversaries."

The latest version also scans profiles in the Thunderbird email client for email addresses and passwords, he wrote. "This will almost certainly be used to further the spam campaign for TorrentLocker," he wrote.

TorrentLocker asks for US$500 to unlock the files, payable in bitcoin. Hummel wrote that although the percentage of people who pay is low, a look at the bitcoin address associated with TorrentLocker showed that the attackers are making "many bitcoins," he wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags NixuSANS InstitutesecurityiSight Partnersmalware

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?