Categories: CryptoNews

Security Researcher Provides Free Decryption of CTB-Faker Ransomware

Once again, there is a new type of ransomware in town, which shows a lot of similarities with the once feared CTB-Locker malware strain. However, this tool does something differently, as it uses WinRAR to lock data in password-protected zip files. This is an interesting take on file encryption, although it may not be as worrisome as people may think at first glance.

CTB-Faker Ransomware Is A Different Breed

Throughout the past few months, internet criminals have been stepping up their game when it comes to creating powerful ransomware. Even though CTB-Faker borrows a lot of its code from CTB-Locker, do not take this threat lightly. Getting infected with this malware will make computer files inaccessible, which is never a good thing.

That being said, it is possible to decrypt the data, although it will take a more complicated process than normal. Interestingly enough, CTB-Faker often spreads through adult websites, particularly those promoting private striptease dance videos. Platform visitors are invited to download a zip file containing an executable file, containing the CTB-Faker ransomware.



So far, this method of attack has proven to be quite lucrative for internet criminals. One of the Bitcoin addresses used by this malware has received 577 BTC in payments so far. Not bad for a rather harmless ransomware, even though it can be quite annoying to deal with for the average user. Paying the ransomware fee of US$50 in Bitcoin is usually the preferred action, as it is a rather small price to pay compared to other forms of malware.

Related Post

Security researchers have discovered the CTB-Faker name is aptly chosen, considering how little of a threat this malware truly poses.  Instead of using SHA-512 and RSA-4096 encryption to lock files, it uses the standard encryption used by the WiNRAR software. One researcher has found a way to break this encryption for free, and he will gladly help infected users do so.

While the ransom note provided by CTB-Faker may be very worrisome, none of its claims can be backed up. Moreover, the low ransom price point makes it appealing to less tech-savvy computer users to just pay the money and have file access restored. But rest assured a free solution is available when reaching out to the right people.

Image credit 1

If you liked this article follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin and altcoin price analysis and the latest cryptocurrency news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Vitalik Buterin Deploys 16,384 ETH Toward Privacy And Open Infrastructure

Ethereum co-founder Vitalik Buterin is once again channeling personal capital into the long-term foundations of…

14 hours ago

Lido V3 Launches on Ethereum Mainnet With Game-Changing stVaults

Lido Finance has officially activated Lido V3 on the Ethereum mainnet, introducing a powerful new…

14 hours ago

Bitcoin Slips To $83,500 As Liquidations Rock The Market

Bitcoin tumbled to around $83,500, marking its lowest level in over a month and triggering…

2 days ago

The 190M Daily Squeeze: ZKP’s $1.6M Momentum Ranks It as the Best Presale Crypto for 10,000x Gains

The Zero Knowledge Proof (ZKP) presale auction has officially entered Stage 2, and for anyone…

2 days ago

Ethereum Signals ERC-8004 Mainnet Launch For AI Agents

Ethereum has announced that ERC-8004, a new token standard designed for AI agents, is heading…

3 days ago

Ondo’s Tokenized U.S. Treasuries Go Live on Sei

Tokenized U.S. Treasuries from Ondo Finance are now live on the Sei Network, marking a…

3 days ago