Categories: NewsSecurity

CryptFile2 Ransomware Obfuscates Infected Files’ Extension to Avoid Decryption

It appears a lot of existing ransomware strains are undergoing some much-needed upgrades as of late. The developers of CryptoMix variant CryptFile2 have introduced some noteworthy changes. All encrypted files will now receive a new file extension, which causes more problems for malware victims. After all, they can no longer easily identify which type of ransomware infected their system in the first place.

CryptFile2 Ransomware Strain makes Life More Difficult

As if victims of malware attacks do not have enough to worry about already, the people responsible for creating CryptFile2 decided to up the ante a bit. Most types of ransomware infections can be easily identified by looking at the encrypted file’s extension. However, the updated CryptoMix variant now removes the proprietary file extension and renames files to the “.wallet” extension. A rather surprising turn of events that will have major consequences.

As a result of this change, malware victims can no longer identify the type of ransomware harming their system. In a way, this should improve the chance of getting paid where criminals are concerned. However, it remains to be seen if the .wallet extension will trick more people into paying the ransom demand due to this change. Consumers are well aware of how paying the ransom is never the right answer.

However, one thing that may cause a problem is how multiple types of malware now use the .wallet extension. CryptFile2 is just one of the many variants to do so, as Dharma, Sanctions, and a few other types of malware use this extension as well. Moreover, one cannot go by the email address listed to communicate with the criminals either, as they show no hint of which malware type is involved.

Related Post

Decrypting files with the .wallet extension is impossible at this stage, unfortunately. It does not matter which ransomware is responsible for the infection, as security engineers have not been able to create a free decryptor for any of the malware types using this extension right now. It is possible a free tool will be made available in the future, though, but for now, restoring data from a backup is the most viable course of action.

As one would come to expect these days, CryptFile2 spreads itself through many different ways. Unfortunately, there is no clear pattern to be detected, which makes it rather difficult for researchers to warn the public about this new threat. Spam emails, malicious Torrent downloads, and malicious links spread via social media are the most likely distribution methods at this stage, though.

What sets CryptFile2 apart from other types of ransomware is how it does not only encrypt specific file extensions. Instead, the malware goes after any file as long as they are not found within specifically whitelisted folders. The criminals will offer free decryption of up to five files to prove they actually control the decryption key for each individual victim. There is no fixed Bitcoin fee associated with decrypting files either, as it will all depend on when the victim contacts the developers.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

TRON Leads All Blockchains in November Fees as Perpetuals Trading Surges 271%

TRON ended November as the top blockchain by fees, extending its dominance in payment infrastructure…

1 day ago

Prediction Markets Hit New All-Time Highs as November Volume Surges to $14.3B

Prediction markets just locked in another breakout month. November closed with $14.3 billion in total…

1 day ago

Trust Wallet Launches Native Predictions: A New Era for On-Chain Betting

Trust Wallet is stepping into a completely new lane. The CZ-owned self-custody wallet has launched…

2 days ago

Kraken Acquires Backed to Supercharge Tokenized Equities as xStocks Enters Its Next Phase

Kraken has announced the acquisition of Backed, the tokenization platform behind some of the fastest-growing…

2 days ago

Sui Pauses & AVAX Rebounds While Zero Knowledge Proof’s 200M Daily Presale Auction Goes Live, Sparking Massive Buyer Rush

Sui Pauses & AVAX Rebounds While Zero Knowledge Proof’s 200M Daily Presale Auction Goes Live,…

3 days ago

Europe Takes Down Cryptomixer: A $1.4B Bitcoin Laundering Machine Falls After Eight Years

Europe just shut down one of crypto’s longest-running shadows. Germany and Switzerland, backed by Europol,…

3 days ago