Menu
CTB-Locker ransomware hits over 100 websites

CTB-Locker ransomware hits over 100 websites

The new threat is written in PHP and encrypts all files in Web server directories

A new malicious program that encrypts files on Web servers has affected at least 100 websites over the past few weeks, signaling a new trend in ransomware development.

The program, which is written in PHP, is called CTB-Locker, a name also used by one of the most widespread ransomware programs for Windows computers. It's not clear though if there's a relationship between this new Web-based ransomware and the Windows version.

Once installed on a Web server, the program replaces the site's index.php and creates a directory called Crypt that contains additional PHP files. It starts to encrypt all the files in the server's Web directory when it receives a specifically crafted request from an attacker.

After the encryption process is complete, the website's home page will display a message asking for a payment to be made in bitcoin.

One of the first attacks with this Web-based version of CTB-Locker was reported on Feb. 12 when the website of the British Association for Counselling and Psychotherapy fell victim to it.

It wasn't immediately clear at the time whether the website was affected by a real ransomware attack or if it was just an attempt to scare the website owners. Some people were understandably skeptical because the CTB-Locker name had previously only been associated with Windows ransomware.

Researchers from Stormshield, a subsidiary of Airbus Defence and Space, have since managed to obtain a full copy of the malicious code from another affected website. In fact they they found 102 websites that have been infected with this Web-based ransomware so far.

It's not yet clear how the attackers gained access to those websites in order to install CTB-Locker. Blaming a specific vulnerability in a popular content management system (CMS) like WordPress is hard, because some of the affected websites did not use a CMS, the Stormshield researchers said in a blog post Friday.

"The infected hosts run both Linux and Windows and the majority of them (73%) host an Exim service (SMTP server)," they said. "Some of them are vulnerable to ShellShock, but without a deep access on victims' servers, it is difficult to understand how this ransomware infected hosts."

Most of the affected websites also had a password-protected Web shell installed. This is a type of backdoor program that attackers install on Web servers once they've gained unauthorized access to them.

CTB-Locker is not the first ransomware to target websites. In November, researchers discovered a similar threat dubbed Linux.Encoder.1, but that program appeared to be experimental and had cryptographic flaws that allowed researchers to create a decryption tool.

It's likely that Linux.Encoder.1 served as inspiration for other ransomware creators, showing that such attacks against Web servers are viable. As such, CTB-Locker will probably not be the last ransomware program to encrypt websites.

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments