Bitcoin Ransomware Education – LTTP

It has been a while since a new ransomware strain was discovered. Rest assured criminals are still coming up with new angles in order to defraud as many people as humanly possible. LLTP Ransomware, also known as LLTP Locker, is targeting Spanish-speaking computer users, which somewhat limits its potential. That being said, ransomware is never fun to deal with, even when it only targets a specific group.

LLTP Ransomware Is An Intriguing Malware Type

Security researchers are pretty convinced the LLTP ransomware strain is based on the VenusLocker ransomware, which was released a while ago. It is not uncommon for cybercriminals to copy someone else’s work, especially where malware is concerned. Additionally, the rise in popularity of ransomware-as-a-service opens the door for the development of new ransomware types based on the same source code.

As one would expect from LLTP Ransomware, the malware will encrypt computer files. However, there is a slight twist, as this malware will go about its business regardless of whether the user is connected to the internet. That is not always the case, as most popular types of ransomware will connect to a command-and-control server before encrypting files. LLTP is doing things a bit differently in this regard, yet that is not the only unique part.

To be more specific, the LLTP ransomware will communicate to a command-and-control server once an online connection is detected. Once the connection is made, the server will respond with an AES password used to encrypt the victim’s files. However, when it does not find the internet connection, the ransomware will generate an AES key on its own. Quite an intriguing development, that much is certain

Related Post

LLTP encrypts files by using different file extensions based on the original extension. Virtually every type of ransomware renames files with the ransom family name as the new extension. While this may seem to be a small change, it goes to show some thought went into developing this new malware strain. This also makes it more difficult for security researchers to create a free LLTP decryption tool, although that situation may come to change in the future.

Recovering from an LTTP infection is proving to be quite difficult, though. As soon as the encryption process has been completed, the shadow volume copies on the computer will be removed. This means restoring files from a backup will be virtually impossible. A handy note will be generated on the desktop to explain what has happened to the computer user. All of this will be done in Spanish, of course, although it is not unlikely we will see more localized versions of this malware in the future

At the time of writing, the LTTP ransomware demands a US$200 payment, to be made in bitcoin. Paying this ransom is never the right course of action, even though there is no other way to get rid of this malware by any means. What is rather intriguing is how the

bitcoin address used for payments seems to be the same for every victim. This is a godsend for Blockchain analysis companies which  may investigate the address. So far, no payments have been made to this address, though.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

FOMO Selling Trigger $1 Billion Liquidations as LINK & SOL Bleed Heavily; What to Do Next?

In the past, Chainlink (LINK) and Solana (SOL) have been among the most discussed altcoins…

3 hours ago

Qubetics $7.4M Presale Revolutionises Blockchain as Bitcoin and Chainlink Drive Innovation: Best Cryptos to Buy for 2025

The crypto market is abuzz with excitement as 2025 approaches. While Bitcoin continues to dominate…

8 hours ago

Best Altcoins to Buy Today: Why Qubetics’ Presale Could Be the Best Investment Opportunity of 2024

The cryptocurrency market never sleeps, and every day feels like an adventure. From household names…

14 hours ago

Forget DOGE and SHIB: These 5 Memecoins Are 2025’s Millionaire Makers

The memecoin craze is evolving, and a new wave of contenders is rising. With fresh…

23 hours ago

While Ethereum Approaches $6K, XYZVerse Prepares for a 16,900% Market Shakeup

As Ethereum's value inches toward unprecedented heights, another digital asset is set to make a…

23 hours ago

Four Meme Coins That Might Disappoint and One That Could Deliver Big Gains

Meme coins are the wild cards of the crypto world—one day they're "to the moon,"…

23 hours ago