24 Jul 2006
Hackers could make ransomware so complex that it will be beyond the decryption capabilities of the antivirus industry, new research has claimed.
A study by Kaspersky Lab warned that authors of ransomware are pushing the boundaries of modern cryptography by using evermore sophisticated encryption algorithms.
Ransomware involves the use of malicious code to hijack user files, encrypt the information and then demand payment in exchange for the decryption key.
The first piece of ransomware to use a sophisticated encryption algorithm, Gpcode.ac, was detected in January and used the RSA algorithm to create a 56-bit key.
Since then, the author of Gpcode has released several increasingly complex variants of the virus and in June released Gpcode.ag, which used a 660-bit key.
"We were able to decrypt 330-bit and 660-bit keys within a reasonably short space of time, but a new variant with a longer key could appear at any time," said Aleks Gostev, senior virus analyst at Kaspersky Lab.
"If RSA, or any other similar algorithm which uses a public key, were to be used in a new virus, antivirus companies might find themselves powerless even if maximum computing power was applied to decrypting the key.
"Unfortunately, the authors behind the Gpcode, Cryzip and Krotten ransomware are still free. But even if they are arrested, there is nothing to prevent other malicious users from implementing such techniques in order to make money.
"In the meantime, antivirus companies have to continue working on proactive protection which will make it impossible for malicious users to encrypt or archive users' data."
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
A senior C# developer is required by a leading investment...
A senior JAVA developer is required by a leading financial...
A leading investment bank are looking for an AGILE JAVA...
A senior C# WPF F# developer is required by a leading...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?