Skip to main content

Critroni: First File-Encrypting Ransomware to Use Tor

July 21, 2014

Critroni: First File-Encrypting Ransomware to Use Tor

SecurityWeek, By Eduard Kovacs

The threat, dubbed "CTB-Locker" and detected as Critroni.A by Microsoft, was initially used against Russian-speaking users, but according to French researcher known as Kafeine, an English version has also been launched recently. The name CTB, which stems from Curve/Tor/Bitcoin, describes some of the key advantages of using this piece of ransomware.

The malware developers claim that the elliptic curve cryptography that's used to encrypt victims' files makes it impossible to decrypt them without paying the ransom. The Tor anonymity network is utilized to hide the malware's command and control (C&C) servers in order to make operations more difficult to disrupt and to protect the identity of the owner, the developers of Critroni said.

According to ThreatPost, this is the first crypto ransomware that uses Tor to protect C&C servers, a technique usually seen in banking Trojans. Furthermore, unlike other threats that rely on the anonymity network, the Tor components are embedded in the malware's body to make it more efficient and to help it avoid detection, said Kaspersky Senior Malware Analyst Fedor Sinitsyn. Read more

Critroni: First File-Encrypting Ransomware to Use Tor

Critroni: First File-Encrypting Ransomware to Use Tor
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases