4 ms·
Threat Spotlight: TeslaCrypt – Decrypt It Yourself
- Errorcod3 11y agoTeslaCrypt, the latest-and-greatest ransomware branch off of the CryptoWall family, claims to the unwitting user that his/her documents are encrypted with "a unique public key generated for this computer". This coudn't be farther from truth. In actuality, the developers of this malware appear to have been lazy and implemented encryption using symmetric AES256 with a decryption key generated on the user's machine. If any of your machines are afflicted, Talos has developed a tool that can be used to generate the user's machine's symmetric key and decrypt all of the ransomed files. (From citpyrc - Slashdot)
- danbruc 11y agoLuckily at least some malware authors suck at cryptography, too. Generate a random symmetric key, encrypt all files with this key, encrypt the symmetric key with an asymmetric public key included in the malware. Game over. At least until someone manages to obtain the private key.
- CJefferson 11y agoHowever, you do lose deniability -- if you have possession of that key, you have to explain it. There might be more value in not requiring you keep track of a key, at the loss of some users who figure out how to unencrypt themselves (of course, I might be overestimating malware authors!)
- sarciszewski 11y ago> However, you do lose deniability -- if you have possession of that key, you have to explain it. Full disk encryption + encrypted VMs that are powered down when not in use + religious adherence to TOR and basic OpSec common sense -> deniability is almost irrelevant
- Derpdiherp 11y agoAssuming that TOR isn't safe - which there's strong evidence to believe at the moment, and you can track down who's involved, crypto becomes as strong as the resistance to pain of the people involved.
- sarciszewski 11y ago> Assuming that TOR isn't safe - which there's strong evidence to believe at the moment There actually isn't strong evidence here, but regardless you should be proactively paranoid anyway.
- danbruc 11y agoThere is no need to be in possession of the private key - only put in on the C&C server or even let the C&C server generate the key pair and send out the public key on request.
- Phlarp 11y agoUltimately the goal of ransomware is to obtain bitcoins, which are really just value stored in a key you possess, so this problem is nearly intractable as far as maintaining complete deniability. To say nothing of turning those coins into USD you can legally spend.
- GlickWick 11y agoIn the end it hardly matters. People developing malware like this are usually in countries that don't have any cyber crime laws, so they don't need to be incredibly good at covering their tracks to begin with.
- malwareforme 11y agoPost analyzing a recent sample of TeslaCrypt here: http://www.malwarefor.me/2015-04-27-angler-ek-pushes-teslacrypt-0-3-6-ransomware/ http://www.malwarefor.me/2015-04-27-angler-ek-pushes-teslacr...