{"id":397,"date":"2015-07-15T01:22:07","date_gmt":"2015-07-15T01:22:07","guid":{"rendered":"http:\/\/www.dogoodsoft.com\/blog\/?p=397"},"modified":"2024-12-23T07:52:02","modified_gmt":"2024-12-23T07:52:02","slug":"new-version-of-teslacrypt-changes-encryption-scheme","status":"publish","type":"post","link":"https:\/\/www.dogoodsoft.com\/blog\/new-version-of-teslacrypt-changes-encryption-scheme-397\/","title":{"rendered":"New Version of Teslacrypt changes encryption scheme"},"content":{"rendered":"<p><a href=\"https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2015\/07\/shutterstock_163066760-680x400.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-398 size-full\" src=\"https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2015\/07\/shutterstock_163066760-680x400.jpg\" alt=\"New Version of Teslacrypt changes encryption scheme\" width=\"680\" height=\"400\" srcset=\"https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2015\/07\/shutterstock_163066760-680x400.jpg 680w, https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2015\/07\/shutterstock_163066760-680x400-300x176.jpg 300w, https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2015\/07\/shutterstock_163066760-680x400-2x1.jpg 2w\" sizes=\"auto, (max-width: 680px) 100vw, 680px\" \/><\/a><\/p>\n<p>A new version of the nasty TeslaCrypt ransomware is making the rounds, and the creators have added several new features, including an improved encryption scheme and some details designed to mimic CryptoWall.<br \/>\nTeslaCrypt is among the more recent variants of ransomware to emerge and the malware, which is a variant of CryptoLocker, is unique in that it targets files from gaming platforms as well as other common file types. Version 2.0.0 of TeslaCrypt discovered recently by researchers at Kaspersky Lab, no longer uses a typical GUI to show users the warning about their files being encrypted. Instead, the malware opens a page in the user\u2019s browser to display a warning message that is taken directly from CryptoWall.<\/p>\n<p>That change, researchers speculated, could be a way to make TeslaCrypt seem more intimidating.<\/p>\n<p>\u201cWhy use this false front? We can only guess \u2013 perhaps the attackers wanted to impress the gravity of the situation on their victims: files encrypted by CryptoWall still cannot be decrypted, which is not true of many TeslaCrypt infections,\u201d Fedor Sinitsyn of Kaspersky Lab wrote in an analysis of the new ransomware.<\/p>\n<p>But the more significant modification in version 2.0.0 is the inclusion of an updated encryption method. TeslaCrypt, like many other ransomware variants, encrypts the files on victims\u2019 machines and demands a payment in order to obtain the decryption key. The payment typically must be in Bitcoin and the attackers using crypto ransomware have been quite successful in running their scams. Estimates of the revenue generated by variants such as CryptoLocker run into the millions of dollars per month.<\/p>\n<p>Researchers have had some success in finding methods to decrypt files encrypted by ransomware, specifically TeslaCrypt. But the change to the malware\u2019s encryption method may make that more difficult.<\/p>\n<p>\u201cThe encryption scheme has been improved again and is now even more sophisticated than before. Keys are generated using the ECDH algorithm. The cybercriminals introduced it in versions 0.3.x, but in this version it seems more relevant because it serves a specific purpose, enabling the attackers to decrypt files using a \u2018master key\u2019 alone,\u201d Sinitsyn said.<\/p>\n<p>\u201cEach file is encrypted using the AES-256-CBC algorithm with session_priv as a key. An encrypted file gets an additional extension, \u2018.zzz\u2019. A service structure is added to the beginning of the file, followed by encrypted file contents.\u201d<\/p>\n<p>The TeslaCrypt authors also took out the decryption mechanism in the malware that researchers were able to exploit in previous versions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new version of the nasty TeslaCrypt ransomware is making the rounds, and the creators have added several new features, including an improved encryption scheme and some details designed to mimic CryptoWall. TeslaCrypt is among the more recent variants of ransomware to emerge and the malware, which is a variant of CryptoLocker, is unique in &hellip; <a href=\"https:\/\/www.dogoodsoft.com\/blog\/new-version-of-teslacrypt-changes-encryption-scheme-397\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">New Version of Teslacrypt changes encryption scheme<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[149,150,152,151],"class_list":["post-397","post","type-post","status-publish","format-standard","hentry","category-news","tag-cryotwall","tag-cryptolocker","tag-encryption-scheme","tag-malware"],"_links":{"self":[{"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/posts\/397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/comments?post=397"}],"version-history":[{"count":1,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/posts\/397\/revisions"}],"predecessor-version":[{"id":399,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/posts\/397\/revisions\/399"}],"wp:attachment":[{"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/media?parent=397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/categories?post=397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/tags?post=397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}