• Cloud & Hosting
    • Public Cloud
    • Private Cloud
    • Hybrid Cloud
    • Transition to the Cloud
    • Hosted Desktop
    • Hosted Telephony
    • Application Hosting
  • IT Support
    • User Support
    • Server Support
    • Infrastructure & Network Support
    • Public Cloud Support
    • IT Consultancy
    • Backups & Business Continuity
  • Cyber Security
    • Managed Antivirus
    • Mobile Device Management
    • Patch Management
    • Security Audit
    • Training
  • Company
    • About Us
    • Contact Us
    • News

CryptoLocker Virus Update

Posted on January 16, 2020

CryptoLocker is a Trojan that encrypts files on an affected system. It first appeared on the Internet in 2013 and was targeted at Windows-based platforms. Once downloaded and activated, it looks for certain file types to encrypt using RSA public key cryptography.

How did this happen?

CryptoLocker usually spreads through a botnet or by way of compromised email attachments. This is usually triggered once an email attachment is opened.

Our Response?

Our technicians got an immediate alert and acted straight away as per our usual processes.

Elements of the platform closed down automatically and we were alerted it was a Crypto virus instance.

All access to email and OWA was automatically suspended to stop the spread of the virus to users as designed. This version of Crypto locker (Ryuk Ransomware) works very quickly and some files were affected in the short time between activation and shut down.

Our status page was updated immediately to show customers that email access was closed down and to advise of the DR links.

With the very nature of crypto we needed to deny access to areas of the platforms, so we could clean and restore the data and services throughout to maintain full security.

The whole system was up and running by Monday morning by 3.30am. Scanning was continuous and you may have noticed the platform was running slower than usual. These scans discovered HTML files that should have not have been there. These are not viruses.

Upon discovering these HTML files, and following a risk assessment, we decided to remove all data that contained these files.

Therefore, below are some recommendations on how to avoid malware:

  • The more files your user account has access to; the more harm malware can inflict. Therefore, restricting access is a prudent course of action, as it will decrease the scope of what can be encrypted. Besides offering a line of defence for malware; it also mitigates potential exposure to other attacks from both external and internal actors.
  • You should take note of emails from senders you do not know, especially those with attached files.
  • Disabling hidden file extensions in Windows can also help recognize this type of attack.
  • Having a backup system in place for your critical files help to mitigate the damage caused not only by malware infections but also hardware problems or any other incidents as well.
  • Continuous user education is key.

Want more information about Citadel Technology Managed Services?

For more information about IT Support, Cloud & Hosting, IT Consultancy, Infrastructure Support, Server Support, Cloud Transition, or anything else on this site, please give us a call on 0345 340 2120 or send us a message via our contact page.

Next Post
Weather Matters

Recent Posts

  • Understanding the UK ISDN Switch-Off: A Guide for SMEs March 24, 2025
  • End of Life (EOL) For Microsoft Windows 10 Home and Pro March 19, 2025
  • Top 3 Myths About Moving To The Cloud February 20, 2025
  • Are you ready for managed services? January 5, 2025
  • Support Opening times for Christmas 2024 December 16, 2024

Categories

  • Cloud Services (7)
  • Hosted Desktop (1)
  • Hosted Telephony (1)
  • Uncategorised (43)

Want to Find
Out More?

Call us for a free discovery chat and see how citadel technology can help your business. Give us your it problem and we can provide the solutions!

email

[email protected]

phone

0345 340 2110

linkedin
x twitter
linkedin
x twitter

First Name
Last Name
Email Address
Company
Phone

Some of our Technology Partners

Bitdefender
Veeam
Sage
Citadel logo

email

[email protected]

phone

0345 340 2110

linkedin
x twitter
Cyber Essentials Certified

IT Services

Public Cloud Support
IT Support
Infrastructure & Network Support
Server Support
User Support

Cloud Services

Microsoft 365
MICROSOFT AZURE
Hosted VoIP
HOSTED SERVER
Citadel Connect
Hosted Desktop
Citadel logo

email

[email protected]

phone

0345 340 2110

linkedin
x twitter
Cyber Essentials Certified

IT Services

Public Cloud Support
IT Support
Infrastructure & Network Support
Server Support
User Support

Cloud Services

Microsoft 365
MICROSOFT AZURE
Hosted VoIP
HOSTED SERVER
Citadel Connect
Hosted Desktop

2024 Citadel Technology. All rights reserved

Privacy