Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Researchers detect new and improved Cryptowall ransomware

by The Gurus
October 3, 2014
in Editor's News
Share on FacebookShare on Twitter

A new version of the Cryptowall ransomware may be about to hit businesses and consumers, with suspicion that the first version was just a test.
 
According to research by F-Secure, the first samples of ransomware calling itself “CryptoWall 2.0” were spotted in the wild. It said that CryptoWall 2.0 appears to use a new packer/obfuscator with an increased amount of anti-debugging and anti-static analysis tricks. However upon infection, CryptoWall 2.0’s payload is almost identical to the samples seen in the original version earlier this summer.
 
Sean Sullivan, security advisor at F-Secure, told IT Security Guru that the different packer/obfuscator on the shell is the same, but the outside is different, meaning that static detection will not detect it and a modern anti-virus that runs an emulated sandbox will detect it.
 
“For most organisations, that repacking and obfuscation will be a problem,” he said. “The unique obfuscation would be spotted by our product and not let it run, but businesses do not like a cloud query and it is usually locked down by firewalls. Businesses don’t use the modern features and are not protected; consumers would be if they have the latest and greatest technology.”
 
Asked if those who were protected against the first version would be protected here, Sullivan said they would from the core if their anti-virus runs a sandbox, as the behavioural engine would be able to detect it.
 
“One layer should be able to detect it, but it depends on how good the anti-virus is at looking at the individual layers,” he said. “A lot of businesses rely on the static signature layer, which is not really good enough.”
 
Troy Gill, manager of security research at Appriver, said that it had seen the recent push of Cryptowall and since the 1st October, it had quarantined just over five hundred thousand of these messages, which is obviously only a small portion of the actual traffic from this group.
 
He said: “Since businesses rely heavily upon signature-based malware detection, unfortunately it is still possible for those protections to be evaded. In this case the original email contains a smaller ‘dropper’ type program.
 
“Once the dropper has gained a foothold on the victim’s machine it will reach out to download additional malware. Cyber criminals are constantly repackaging their software in an attempt to evade anti-virus systems. So while the initial infection vector can change, the payload can remain the same.”
 
Asked if he felt that this would resurrect the trend of ransomware after a “strong” trend in early 2014, Sullivan said he felt it could as CryptoLocker’s distribution was cut off due to the GameOver Zeus takedown, and that suspended things.
 
“We are seeing a trend, as banks as protecting against man-in-the-middle attacks and the trend is moving from banking transactions being secure from client to server,” he said.
 
“The bad transactions are also blocked, so ransomware is an option as CryptoLocker did a job in the English language and it is a learning curve and once they manage that, they are off to the races as the money is on the table. The bots have been converted and it is the most effective way of monetising those bots that belong to consumers and small businesses.”
&
nbsp;
Gill said: “Ransomware, like Cryptowall, never really went away but there was a period of relative calm over the summer months. This ebb and flow of malicious activity is the norm in the malware underworld.
 
“Just like legitimate developers, malware authors need to take time to go through development phases as well. This new brand of aggressive style ransomware has proven quite effective, so it is not going anywhere any time soon.”
 
He recommended having solid security measures in place to protect against this infection and also maintain a backup system that can mitigate any damage caused by this malware(this goes for everyone and not just the enterprise).
 
TK Keanini, CTO of Lancope, said that regardless of the version, one thing that is true is that a proper backup of the file system on a regular basis is the best countermeasure. “These attackers are banking on the fact that no one practices good backup procedures,” he said.

Tags: CryptowallF-SecureRansomware
ShareTweet
Previous Post

Why no data is OK to lose

Next Post

JP Morgan Chase – another breach, where is the security?

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol