Cryptolocker - still!

This post is probably a month overdue, but better late than never.

So #Cryptolocker is back again, with the same M.O. as last year, but with a slight twist. You still get an email with very bad grammar about a non-delivered parcel. At this point, all your end-user security training should be paying off - bad grammar, spelling mistakes and a link for a parcel you are probably not expecting. But nevertheless, they click away. A site that looks like auspost.com.au, but is probably parceltracker-24.net or similar, invites you to enter a Captcha code and download a file. The twist is the file is delivered from a file sharing site (like disk.yandex.com or cubbyusercontent.com) over encrypted HTTPS, thus bypassing most gateway inspection. My advice: seriously think about selective HTTPS inspection and block 'Network Storage and Personal Backups" as a category with exceptions for the ones you commonly use, such as iCloud, Google Drive, Microsoft OneDrive and Dropbox. Creating exceptions and/or deploying decryption certificates is still less IT work than recovering from Ransomware.

To view or add a comment, sign in

More articles by Robert Collins

  • Life's too Short for Bad Java

    If you use a computer, you’ve probably heard of Java. It’s a technology to allow active content in your browser when…

  • Australia welcomes Netflix and Netflix scams

    The popularity of Netflix in Australia has not been overlooked by hackers. Spoofing various provider domains for…

  • Two NSS Labs Recommended products in one

    Congratulations to LastLine, who scored a 'Recommended' rating (the highest) from NSS Labs for Breach Detection…

  • Android Ransomware

    I saw today in ARN: “More than 25 per cent of all reported malware in May was Android ransomware, according to security…

  • WatchGuard M series – why firewalls need to keep getting faster

    Many observant customers and WatchGuard systems integrators have mentioned to me how much faster the new M series…

    4 Comments

Explore content categories