New Ransomware Masquerading as COVID-19 Tracing App

CryCryptor targeting Android users in Canada; ESET researchers find decryption tool for victims of cyberattack

Photo: Bigstock

New ransomware is being used in cyber-attacks under the guise of an official Canadian COVID-19 tracing app, security researchers from ESET announced this past week.

"CryCryptor," the new ransomware has been targeting Android users in Canada and is being distributed via two websites under the pretext of an official COVID-19 tracing app provided by Health Canada.  The researchers said the ransomware surfaced just a few days after the Canadian government officially announced its backing of a nation-wide voluntary tracing app called COVID Alert.

The app is set for testing in the province of Ontario beginning next month.

ESET said in a post on its website that it had informed the Canadian Centre for Cyber Security about the threat.

"Once the user falls victim to CryCryptor, the ransomware encrypts the files on the device – all the most common types of files – but instead of locking the device, it leaves a “readme” file with the attacker’s email in every directory with encrypted files," ESET website stated.

Fortunately, ESET researchers were able to create a decryption tool for victims of this ransomware attack.

img
Rare-earth elements between the United States of America and the People's Republic of China
The Eastern seas after Afghanistan: the UK and Australia come to the rescue of the United States in a clumsy way
The failure of the great games in Afghanistan from the 19th century to the present day
Russia, Turkey and United Arab Emirates. The intelligence services organize and investigate