CryptoWall

Description

(SecureWorks) After the emergence of the infamous CryptoLocker ransomware in September 2013, CTU researchers observed an increasing number of ransomware families that destroyed data in addition to demanding payment from victims. While similar threats have existed for years, this tactic did not become widespread until CryptoLocker’s considerable success. Traditionally, ransomware disabled victims’ access to their computers through non-destructive means until the victims paid for the computers’ release.

Early CryptoWall variants closely mimicked both the behavior and appearance of the genuine CryptoLocker. The exact infection vector of these early infections is not known as of this publication, but anecdotal reports from victims suggest the malware arrived as an email attachment or drive-by download. Evidence collected by CTU researchers in the first several days of the February 2014 campaign showed at least several thousand global infections.

Names

Name
CryptoWall

Category

Malware

Type

  • Ransomware

Information

Malpedia

Other Information

Uuid

8f6a401d-bf9b-42d0-8faf-57e65ba63149

Last Card Change

2020-04-23