Skip to Content
Ransomware
book

Ransomware

by Allan Liska, Timothy Gallo
November 2016
Beginner to intermediate
187 pages
5h 18m
English
O'Reilly Media, Inc.
Content preview from Ransomware

Chapter 9. CryptXXX

The CryptXXX ransomware first appeared at the end of March 2016 and quickly grew into one of the most popular ransomware families delivered via exploit kit. Currently, CryptXXX is primarily delivered via web exploitation kits using compromised websites and malware-infected advertisements.

It was first reported on by researchers at Proofpoint in conjunction with Frank Ruiz from Fox IT InTELL.1 The team behind CryptXXX made extensive use of the Angler exploit kit using the Bedep loader for earlier versions but, with the demise of Angler, moved on to other exploit kits in recent versions.

CryptXXX is also unique in that earlier versions of CryptXXX were delivered in DLL format rather than as an executable. Running the ransomware as a DLL instead of a PE often allows the CryptXXX family to bypass traditional antivirus solutions because the DLL will make calls to legitimate Windows system executables on the victim machine. Unless the antivirus program knows to look for suspicious DLL activity, CryptXXX will remain undetected until the encryption process is complete and the ransom note pops up.

CryptXXX is now primarily delivered via the Neutrino exploit kit, which targets vulnerabilities in three different Windows applications:

  • Adobe Flash
  • Microsoft Silverlight
  • Java and Java Runtime Environment (JRE)

CryptXXX also does more than just encrypt the files on a victim machine. Because the initial deployments used the Angler exploit kit and Bedep Loader, the CryptXXX ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Ransomware

Ransomware

Allan Liska, Timothy Gallo

Publisher Resources

ISBN: 9781491967874Errata Page