CTB-Locker ransomware hits over 100 websites

A new malicious program that encrypts files on Web servers has affected at least 100 websites over the past few weeks, signaling a new trend in ransomware development.

The program, which is written in PHP, is called CTB-Locker, a name also used by one of the most widespread ransomware programs for Windows computers. It’s not clear though if there’s a relationship between this new Web-based ransomware and the Windows version.

Once installed on a Web server, the program replaces the site’s index.php and creates a directory called Crypt that contains additional PHP files. It starts to encrypt all the files in the server’s Web directory when it receives a specifically crafted request from an attacker.

To read this article in full or to leave a comment, please click here

Read more: CTB-Locker ransomware hits over 100 websites

Story added 29. February 2016, content source with full text you can find at link above.