Backups or Bust: Surviving the CryptoLocker Scare

Backups or Bust: Surviving the CryptoLocker Scare

Tutorials backups cryptolocker ransomware security windows

My brother-in-law called me Tuesday night sounding like someone had died. Turns out something kind of had, or at least every spreadsheet and invoice PDF in his little bookkeeping business had. One of his employees had opened a zip file attached to an email that looked like a FedEx delivery notice, and about twenty minutes later a red window popped up telling them their files were now encrypted with RSA-2048 and they had 72 hours to pay $300 in Bitcoin or a MoneyPak voucher or the private key would be destroyed forever.

That's CryptoLocker, in case you haven't run into it yet. If you're reading a tech blog in November 2013 you've probably at least heard the name by now, its been making the rounds since September and it's picking up speed. I'm not going to pretend I know exactly how many machines it's hit (the numbers I've seen thrown around are all over the place and I don't trust any of them), but I know it's real because I watched my brother-in-law's countdown timer myself over a shaky phone video.

Here's the part that actually matters and that a lot of the coverage glosses over: the encryption is not a bluff. This isn't some scareware popup with a fake progress bar. It genuinely encrypts your files with a strong enough key that there is currently no known way to crack it without the private key sitting on the attacker's server. Antivirus companies can clean the infection off your machine easily enough. That does nothing for your files. Removing the malware and getting your documents back are two completely separate problems, and I think that distinction is what trips people up.

So what do you actually do. First, and I cannot stress this enough: back up your stuff to something that isn't permanently attached to your computer. CryptoLocker will happily chew through any mapped network drive it can reach, so a NAS that's always mounted is not meaningfully safer than your C: drive. An external USB drive that you plug in, back up to, and unplug is boring and old-fashioned and it works. Cloud backup that keeps prior versions (not just a synced folder, an actual versioned backup) works too, since you can roll back to before the infection.

Second, there's a free tool called CryptoPrevent from a guy named Nick Shaw over at FoolishIT that's been going around IT forums this month. It works by setting Windows Software Restriction Policies to block executables from launching out of the AppData and Temp folders, which is where this particular malware family likes to run from. It's not a magic shield and I'd bet money the next variant routes around it eventually, but it's a five-minute install and it's free, so there's no real reason not to run it on a family member's PC before you're the one getting the panicked phone call.

Third, and this is my genuine pet peeve about Windows going back years: turn on "show known file extensions." It's off by default, which means a file named invoice.pdf.exe just shows up as invoice.pdf with a generic icon, and normal people have zero chance of catching that. I've been telling people to flip this setting since XP and I will keep telling them until Microsoft just fixes the default, which at this rate feels like it's never happening.

As for whether you pay the ransom if it's too late: I'm not going to lecture anyone who did. It's easy for me to say "never pay, it just funds more of this" from my armchair, but if those are ten years of client tax records and you've got no backup, $300 in Bitcoin starts looking pretty reasonable compared to the alternative. My brother-in-law didn't pay, as it happens, because it turned out his accountant kept a duplicate set of the current quarter's files on her own laptop and they lost about six weeks of less-critical stuff instead of everything. Lucky, not smart. He's got an external drive on his desk now that actually gets used.

Everyone this week is talking about PS4 review embargoes lifting and watching the Twitter stock ticker do its thing, and fair enough, that's the fun stuff. This is the unfun stuff, but it's the kind of unfun that actually costs people money and sleep, so it seemed worth the space today instead.