New Version Of TeslaCrypt Ransomware Features Unbreakable Encryption

Security researchers have found a new variant of the ransomware trojan TeslaCrypt, which uses stronger encryption that makes files impossible to recover. Here’s what you need to know.

Encryption lock image from Shutterstock

TeslaCrypt first appeared one year ago and initially targeted computer gamers but has now evolved to attack businesses and individuals. The newest version that has been found, TeslaCrypt 4.0, has been beefed up to use the RSA 4096 algorithm, making it impossible to break any files encrypted by the ransomware. Larger files, which proved a challenge for older TeslaCrypt ransomwares, can now be encrypted as well.

As well as augmented encryption, TeslaCrypt 4.0 is also able to send more files back to cybercriminals from the infected device compared to its predecessors. This new variant cannot be removed by the TeslaDecoder tool that was used on previous versions.

According to Heimdal Security researchers, you can recognise TeslaCrypt by the following indicators of compromise:

%UserProfile%DesktopRECOVER[%5 random signs%].html
%UserProfile%DesktopRECOVER[%5 random signs %].png
%UserProfile%DesktopRECOVER[%5 random signs %].txt %UserProfile%Documents[random file name].exe %UserProfile%Documentsrecover_file.txt

The ransomware also creates the following value in the registry:

HKCUSoftwareMicrosoftWindowsCurrentVersionRun_[random name] C:WindowsSYSTEM32CMD.EXE /C START %user account%Documents[random name].exe

If you are unfortunate enough to be hit by TeslaCrypt, we hope you have backed up your precious data. Your only options are to restore data from a secure backup or pay the ransom, which most security experts recommend against.

[Via Heimdal Security]


The Cheapest NBN 50 Plans

Here are the cheapest plans available for Australia’s most popular NBN speed tier.

At Lifehacker, we independently select and write about stuff we love and think you'll like too. We have affiliate and advertising partnerships, which means we may collect a share of sales or other compensation from the links on this page. BTW – prices are accurate and items in stock at the time of posting.

Comments