Malware Alert
RECEIVED FROM MY IT GUY
Threat Level: High
Geographical Distribution: Very High
Removal: Difficult
Affected Systems: Windows XP, Vista, 7, 8, All Windows Server OS
Information:
Two new variants of the CryptoLocker malware that was in the news last fall have begun circling the internet. The two variations are known as CryptoWall and CryptoDefense. They operate in a similar manner to Cryptolocker by encrypting the files on your network shares and denying users access until they pay the ransom between $300 and $1000 or restore their files from backup. This is a wide spread attack with a high distribution rate.
The current variant is being spread by email that appears to come from UPS or from a faxing service. The email either contains an attachment or a link to a website to open the notification, which then downloads the virus. Many antivirus vendors do not yet have definitions and these emails often slip by spam filters.
Recommendations:
We are recommending all clients notify their users to be wary of suspicious emails appearing to come from UPS or about faxing and also verify they have current backups. If you see any indication of malicious behavior immediately shutdown the infected machine and disconnect from the network.
|