Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - vxCrypter: The First Ransomware To Delete Duplicate Files
News & Analysis

vxCrypter: The First Ransomware To Delete Duplicate Files

ISBuzz TeamBy ISBuzz TeamApril 2, 2019Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
unmanaged contents
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The vxCrypter Ransomware could be the first ransomware infection that not only encrypts a victim’s data, but also tidy’s up their computer by deleting duplicate files.    

When the ransomware was first tested, it deleted every file in a folder except for one.  As this ransomware was still being developed, it was assumed that this was just a bug in the encryption routine. However, it has been confirmed that this deletion of files was intentional as the ransomware was deleting duplicate files. This was the first ransomware that the researchers have seen that performed this behaviour. 

Experts Comments Below:  

Colin Little,  Senior Threat Analyst at Centripetal:

“Ransomware is a perfect example of how an unskilled operator can cause massive amounts of damage to an organization, all in an effort to monetize their criminal efforts. The good news is that since ransomware is an established malware family, there’s a lot of threat intelligence available to identify and combat it. The files involved, the locations on the endpoint those files are written to, the email or website used to deliver the malicious payload, the server it uses for command and control, all are typically re-used infrastructure. This means that if an organization is proactively using threat intelligence, they can stop an attack like this before it starts even if their conventional security tools miss it. “  

Pravin Kothari, CEO at CipherCloud:

“Malware continues to grow in sophistication and the newer forms of ransomware are particularly deadly to most business.  

SamSam, a custom infection ransomware, has been used in targeted attacks going back to 2016, and has wrecked havoc on city networks from Georgia, Indiana and Colorado.  It has been increasing the cost of their ransom as well.  It spreads using a range of exploits or brute-force tactics. In 2018, SamSam was enhanced to exploit vulnerabilities in remote desktop protocols (RDP), Java web servers, or FTP servers to gain access to victims’ network. Ability to perform brute force attack against weak passwords was also added.  

Given the focus of SamSam on cities, Albany’s ransomware seems to be SamSam or one of its variants. 

To better combat malware, enterprise organizations have been improving their awareness training and security processes with real-time monitoring, backups, cloud security brokers, email security, strong passwords, and rights management to protect their data. This ensures that ransomware can be tackled in real-time or near real-time, so that the data cannot be stolen during a cyber attack or an attempt to compromise data by ransomware- wielding cyber thieves. Encryption and rights management are necessary to be certain that a ransomware attack has not compromised regulated data as required by regulatory requirements of HIPAA,PCI, GDPR, etc. 

Progress to address these threats has been OK but the attackers still move faster than the defenders in this cat-and-mouse game. Enterprise security operations centers (SOC) now usually budget for specific ransomware detection and remediation software. This software protects against the most common ransomware attack vectors, but of course, won’t immediately meet the rapid evolution of ransomware advancements, especially with AI.  Once again, small and medium organizations are more vulnerable and poorly equipped to deal with nation-state sponsored or organized crime sponsored ransomware attacks.” 

Roy Rashti, Cybersecurity Expert at BitDam: 

“Decryption can take time when it comes to large quantities of data. By encrypting solely unique files, the vxCrypter ransomware can speed up this process. In addition, the prospect of losing files that hold valuable information could intimidate the affected end user into paying the ransom.   

To prevent this from happening, users should stay alert and make sure they have proper security solutions in place. Keeping a backup of any important files in a trusted location is also a good habit to get into.    

Ransomware is a major source of income for cybercriminals. This means they are constantly innovating and investing in new attack methods to overcome target organisations’ security solutions. Rather than reacting once an attack has taken place, organisations must always be on guard and be prepared for any possible scenario.”
 

 

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}