NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
Ransomware Will Win The War
The well respected Antivirus firm Kaspersky Lab is calling for a massive group effort to break the encryption used by the latest Ransomware. They're asking competitors, governments, and cryptographers to join the effort. But even a massive worldwide computer grid won't win this war.No Longer Supported
The malware being battled is called Gpcode. Gpcode is a Trojan that is sent through email or posted on USENET newsgroups. The infected attachment is a MS Word .DOC file and most users still think DOC files are safe to open. When its run it encrypts the users documents.

"The email had an MS word .doc file called anketa.doc attached. (Anketa is the Russian for application form). This file actually contained a malicious program called Trojan-Dropper.MSWord.Tored.a. When the recipient opens the attachment, a malicious macro installs another Trojan - Trojan-Downloader.Win32.Small.crb - on the victim machine." - Virulist.com


Gpcode searches for over 80 different file types on the computer and encrypts them. Besides the normal document files Gpcode also encrypts the users email database files. The program leaves behind a text file instructing the person how to contact the author to purchase the decoder program. The program also deletes references to its self. Gpcode has gone through several revisions, the encryption keys in previous versions was found relatively quickly because of flaws in how the author implemented the encryption. This latest version, first reported on June 4th, 2008, apparently does not have these flaws and all efforts to date to find other such shortcuts to crack the encryption key have failed.

"Different versions of the Gpcode virus encrypt user files of different types (.doc, .txt, .pdf, .xls, .jpg, .png, .cpp, .h etc.) using a strong RSA encryption algorithm with different key lengths. After encrypting files on a computer, the virus automatically generates a message informing the user that the files have been encrypted and demanding payment for a decryption utility." - Kaspersky Lab


Even if Kaspersky manages to find a weakness in the current encryption implementation and finds the encryption key eventually this author (or someone else) will get it right. To date no one has broken a 1024 bit RSA encryption key (what Gpcode currently uses). They have broken a "special" 307 bit key but not a true "proper" 307 bit RSA key. Even that effort took years to accomplish. The last time they broke a proper 155 bit key it took 9 years and quite a bit of computing power. One of the best known cryptanalyst, Bruce Schneier, says that the writing is on the wall for 1024 bit keys and eventually they will be broke. So even if Kaspersky wins this battle they won't win the war against ransomware.

"I hope RSA applications would have moved away from 1024-bit security years ago, but for those who haven't yet: wake up." - Bruce Schneier


If Kaspersky's group can not find a shortcut it will take a massive amount of computing power to accomplish something no one has done before them. In one respect it will be quite an accomplishment, but in reality it really doesn't help much. By the time they break the encryption key the author will have moved on to another key, perhaps one using a 2048 bit key (which is currently well outside the bounds of being able to be broken in our lifetime). Or perhaps the author will switch to AES encryption which is orders of magnitude stronger than RSA. From the ransomware author's point of view switching to a synchronous AES key does present some practical problems with key distribution but they aren't impossible to overcome.

Though there is currently no way to break the encryption used by the Gpcode Trojan Kaspersky does have instructions for restoring some files encrypted by Gpcode. Gpcode currently encrypts a copy of the file and then deletes the original, therefore it may be possible to undelete the original (unencrypted) file. But don't count on getting much back because deleted files will quickly get overwritten by new encrypted files. Your best defense to any unknown threat is a good backup, then you can simply delete the encrypted files and restore them from backup (after removing the infection). Of course keeping MS Office and your antivirus application up to date can help as well.

There are many experts that believe Kaspersky Lab is wildly optimistic in believing that a 1024 bit key can be broken anytime soon. Let us hope Kaspersky is not successful because whenever you visit a SSL webpage it first connects using a RSA 1024 bit key (in order to securely exchange a synchronous RC4 or AES key to encrypt the data). If RSA encryption can be broken quickly anyone using standard SSL certificates will need to upgrade. Previous data transmitted over SSL that may have been recorded will be at risk of compromise.

References:
Kaspersky Lab - Press Release announcing the launch of the Stop Gpcode international initiative.
Schneier on Security - Bruce Schneier's blog. He's 'The Man' when it comes to encryption.
Crypto boffin: writing is on the wall for 1024-bit RSA - The Register: "The largest proper RSA number yet broken was a 200-digit "non-special" number whose two prime factors were identified in 2005 after 18 months of calculations that used over a half century of computer time. The 1024-bit numbers used in RSA encryption are around 100 orders of magnitude bigger than this. The writing may be on the wall for 1024-bit RSA: but as yet, um, nobody can read it."
Virulist.com "Blackmailer: the story of Gpcode" - "Gpcode then scans all accessible directories and encrypts files with certain extensions such as .txt, .xls, .rar, .doc, .html, .pdf etc. It also encrypts mail client databases."
Ransomware resisting crypto cracking efforts - SecurityFocus: "While previous versions have had flawed encryption implementations, the latest version -- Gpcode.ak -- appears to have eliminated the flaws that allowed reverse engineers to find earlier keys."
Kaspersky to try to crack code used in 'blackmailer' virus - CNET.com: "Antivirus software vendor Kaspersky is launching an international effort to try to crack the encryption used in a "blackmailer" virus that locks up data on a victim's computer."



Share or Bookmark this Article Using:
| furl | reddit | del.icio.us | magnoliacom | digg | newsvine | stumble it |


Posted by NIST.org on Monday 16 June 2008 - 05:57:58 | |printer friendly
Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads




Headlines

»CVE-2015-1339 (linux_kernel)
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 al ...
»CVE-2015-7515 (linux_kernel)
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows phy ...
»CVE-2015-8812
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify erro ...
»CVE-2015-8816
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not proper ...
»CVE-2015-8844
The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for a ...
»CVE-2015-8845
The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on ...
»CVE-2015-8852
Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inj ...
»CVE-2016-0211
IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows al ...
»CVE-2016-0774
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport ...
»CVE-2016-1185
The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an a ...
»CVE-2016-1202
Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privil ...
»CVE-2016-1205
Cross-site scripting (XSS) vulnerability in the shiro8 (1) category_freearea_ addition_plugin plugin ...
»CVE-2016-1386
The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) all ...
»CVE-2016-1389
Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to red ...
»CVE-2016-1601
yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty pass ...


Date published: 2016-04-30T04:50:00Z
Details

»FBI Releases Article on Ransomware
Original release date: April 29, 2016 The Federal Bureau of Investigation (FBI) has released ...
»Google Releases Security Update for Chrome
Original release date: April 28, 2016 Google has released Chrome version 50.0.2661.94 to addr ...
»Mozilla Releases Security Updates
Original release date: April 26, 2016 Mozilla has released security updates to address multip ...
»FTC Releases Alert on Earthquake Disaster Email Scams
Original release date: April 20, 2016 The Federal Trade Commission (FTC) has released an aler ...
»Cisco Releases Security Updates
Original release date: April 20, 2016 Cisco has released security updates to address vulnerab ...
»Oracle Releases Security Bulletin
Original release date: April 19, 2016 Oracle has released its Critical Patch Update for April ...
»Symantec Releases Security Updates
Original release date: April 19, 2016 Symantec has released security updates to address vulne ...
»VMWare Releases Security Updates
Original release date: April 14, 2016 VMware has released security updates to address a vulne ...
»IRS Warns Taxpayers About Scams as Tax Deadline Approaches
Original release date: April 13, 2016 The Internal Revenue Service (IRS) has issued a press r ...
»Google Releases Security Update for Chrome
Original release date: April 13, 2016 Google has released Chrome version 50.0.2661.75 to addr ...


Date published: not known
Details

»Paper: How It Works: Steganography Hides Malware in Image Files
A new paper by CYREN researcher Lordian Mosuela takes a close look ...
»Paying a malware ransom is bad, but telling people to never do it is unhelpful advice
The current ransomware plague is one of the worst threats the Inter ...
»VB2015 paper: VolatilityBot: Malicious Code Extraction Made by and for Security Researchers
In his VB2015 paper, Martin Korman presented his 'VolatilyBot' tool ...
»VB2016 programme announced, registration opened
We have announced 37 papers (and four reserve papers) that will be ...
»New tool helps ransomware victims indentify the malware family
The people behind the MalwareHunterTeam have released a tool that h ...
»It's fine for vulnerabilities to have names — we just need not to take them too seriously
The PR campaign around the Badlock vulnerability backfired when it ...
»Blog Throwback Thursday: The Number of the Beasts
The Virus Bulletin Virus Prevalence Table, which ran from 1992 unti ...
»Paper: All Your Meetings Are Belong to Us: Remote Code Execution in Apache OpenMeetings
Security researcher Andreas Lindh recently found a vulnerability in ...
»Throwback Thursday: 'In the Beginning was the Word...'
Word and Excel’s internal file formats used to be something in whic ...


Date published: not known
Details
Main Menu
· Home
Current Security News
 
US-CERT Current Activity

» FBI Releases Article on Ransomware
[29 Apr 2016 07:45pm]

» Google Releases Security Update for Chrome
[28 Apr 2016 06:31pm]

» Mozilla Releases Security Updates
[26 Apr 2016 12:53pm]

» FTC Releases Alert on Earthquake Disaster Email Scams
[20 Apr 2016 03:05pm]

» Cisco Releases Security Updates
[20 Apr 2016 11:12am]

» Oracle Releases Security Bulletin
[19 Apr 2016 02:33pm]

» Symantec Releases Security Updates
[19 Apr 2016 11:30am]

» VMWare Releases Security Updates
[14 Apr 2016 07:08pm]

» IRS Warns Taxpayers About Scams as Tax Deadline Approaches
[13 Apr 2016 04:42pm]

» Google Releases Security Update for Chrome
[13 Apr 2016 03:18pm]

***
US-CERT Alerts

» TA16-105A: Apple Ends Support for QuickTime for Windows; New Vulnerabilities Announced
[14 Apr 2016 01:48pm]

» TA16-091A: Ransomware and Recent Variants
[31 Mar 2016 04:00pm]

» TA15-337A: Dorkbot
[03 Dec 2015 04:40pm]

» TA15-314A: Compromised Web Servers and Web Shells - Threat Awareness and Guidance
[10 Nov 2015 06:12pm]

» TA15-286A: Dridex P2P Malware
[13 Oct 2015 05:23am]

» TA15-240A: Controlling Outbound DNS Access
[28 Aug 2015 11:31am]

» TA15-213A: Recent Email Phishing Campaigns – Mitigation and Response Recommendations
[01 Aug 2015 04:01pm]

» TA15-195A: Adobe Flash and Microsoft Windows Vulnerabilities
[14 Jul 2015 05:13pm]

» TA15-120A: Securing End-to-End Communications
[29 Apr 2015 10:00pm]

» TA15-119A: Top 30 Targeted High Risk Vulnerabilities
[28 Apr 2015 10:00pm]

***
Computerworld Security

» IBM offers advice on how to secure blockchain in the cloud
[29 Apr 2016 11:33am]

» Phishing apps posing as popular payment services infiltrate Google Play
[29 Apr 2016 09:44am]

» Toy maker's website pushed growing ransomware threat
[29 Apr 2016 08:43am]

» Supreme Court approves rule change that expands FBI computer search powers
[29 Apr 2016 04:14am]

» Devs leak Slack access tokens on GitHub, put sensitive business data at risk
[28 Apr 2016 11:53am]

» Estonian man gets 7 years in prison for role in global DNS hijacking botnet
[28 Apr 2016 09:58am]

» ISIS' cyberattack abilities remain unorganized and underfunded -- for now
[28 Apr 2016 09:16am]

» The post-acquisition blues
[28 Apr 2016 07:32am]

» FBI confirms it won't tell Apple how it unlocked terrorist's iPhone
[28 Apr 2016 07:24am]

» House unanimously passes bill to protect email and cloud privacy
[27 Apr 2016 01:50pm]

» IDG Contributor Network: The Humble Hacker’s Book Bundle
[27 Apr 2016 12:00pm]

» Most breaches are still caused by PEBKAC and ID10T errors like falling for phishing
[27 Apr 2016 09:44am]

» Group uses Windows hotpatching method for malware
[27 Apr 2016 07:45am]

» Report says criminals are better communicators than IT staffers
[26 Apr 2016 02:17pm]

» SWIFT banking network warns customers of cyberfraud cases
[26 Apr 2016 10:14am]

***
Microsoft Security Advisories

» 3152550 - Update to Improve Wireless Mouse Input Filtering - Version: 1.1
[22 Apr 2016 01:00am]

» 3137909 - Vulnerabilities in ASP.NET Templates Could Allow Tampering - Version: 1.1
[10 Feb 2016 12:00am]

» 2871997 - Update to Improve Credentials Protection and Management - Version: 5.0
[09 Feb 2016 12:00am]

» 3123479 - Deprecation of SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 1.0
[12 Jan 2016 12:00am]

» 3109853 - Update to Improve TLS Session Resumption Interoperability - Version: 1.0
[12 Jan 2016 12:00am]

» 3118753 - Updates for ActiveX Kill Bits 3118753 - Version: 1.0
[12 Jan 2016 12:00am]

» 2755801 - Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge - Version: 53.0
[05 Jan 2016 12:00am]

» 3057154 - Update to Harden Use of DES Encryption - Version: 1.1
[08 Dec 2015 12:00am]

» 3123040 - Inadvertently Disclosed Digital Certificate Could Allow Spoofing - Version: 1.0
[08 Dec 2015 12:00am]

» 3119884 - Inadvertently Disclosed Digital Certificates Could Allow Spoofing - Version: 1.0
[30 Nov 2015 12:00am]

» 3108638 - Update for Windows Hyper-V to Address CPU Weakness - Version: 1.0
[10 Nov 2015 12:00am]

» 3097966 - Inadvertently Disclosed Digital Certificates Could Allow Spoofing - Version: 2.0
[13 Oct 2015 01:00am]

» 2960358 - Update for Disabling RC4 in .NET TLS - Version: 2.0
[13 Oct 2015 01:00am]

» 3042058 - Update to Default Cipher Suite Priority Order - Version: 1.1
[13 Oct 2015 01:00am]

» 3083992 - Update to Improve AppLocker Publisher Rule Enforcement - Version: 1.0
[08 Sep 2015 01:00am]

***
WIRED

» Security News This Week: The FBI Gets Creative to Avoid Disclosing Its $1M iPhone Hack
[30 Apr 2016 05:00am]

» It May Soon Be a Lot Harder for the Law to Get Into Your Email
[29 Apr 2016 01:18pm]

» We’re Going HTTPS: Here’s How WIRED Is Tackling a Huge Security Upgrade
[28 Apr 2016 10:00am]

» The Critical Hole at the Heart of Our Cell Phone Networks
[28 Apr 2016 05:00am]

» Hacker Lexicon: What Is HTTPS?
[27 Apr 2016 08:00am]

» Two Tips to Keep Your Phone’s Encrypted Messages Encrypted
[26 Apr 2016 07:00am]

» Hack Brief: Site for ‘Beautiful’ People Suffers Ugly Million-Member Breach
[25 Apr 2016 12:38pm]

» Security This Week: If You Sue Ashley Madison, You’ll Have to Use Your Real Name
[23 Apr 2016 05:00am]

» The Ingenious Way Iranians Are Using Satellite TV to Beam in Banned Internet
[22 Apr 2016 05:00am]

» FBI Hints It Paid Hackers $1 Million to Get Into San Bernardino iPhone
[21 Apr 2016 02:26pm]

***
Network World Security

» Cybereason gains Lockheed Martin's Threat Intelligence to thwart cyberattacks
[30 Apr 2016 05:31pm]

» FBI: Ransomware threat at all-time high; how to protect company jewels
[29 Apr 2016 10:56am]

» IBM offers advice on how to secure blockchain in the cloud
[29 Apr 2016 09:07am]

» Toy maker Maisto’s website pushed growing CryptXXX ransomware threat
[29 Apr 2016 08:19am]

» What users love (and hate) about 4 leading firewall solutions
[25 Apr 2016 01:48pm]

» 10 no-cost home security mobile apps worth a download
[01 Apr 2016 06:39am]

» 7 VPN services for hotspot protection
[14 Mar 2016 04:00am]

» Review: Consider VPN services for hotspot protection
[14 Mar 2016 04:00am]

» Review: 5 application security testing tools compared
[01 Mar 2016 01:29pm]

» Skyport eases the pain of deploying and securing remote servers
[29 Feb 2016 04:00am]

» Review: 8 password managers for Windows, Mac OS X, iOS, and Android
[24 Feb 2016 05:58am]

» What users love (and hate) about 4 leading identity management tools
[22 Feb 2016 06:52am]

» REVIEW: Cyphort makes advanced threat protection easier than ever
[25 Jan 2016 04:00am]

» IBM offers advice on how to secure blockchain in the cloud
[29 Apr 2016 09:07am]

» Toy maker Maisto’s website pushed growing CryptXXX ransomware threat
[29 Apr 2016 08:19am]

***


More IT Security
News Feeds
More Sponsors

Advertise on this site
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
Symantec News

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}