CTB Locker

Malware

⚠️ Overview

CTB Locker (Curve-Tor-Bitcoin Locker) is a ransomware family first discovered in June 2014 by Intel Security (now McAfee). It was likely developed by the same criminal group behind the earlier Critroni ransomware, operating as ransomware-as-a-service. CTB Locker belongs to the crypto-ransomware category, encrypting victim files using a combination of RSA 2048-bit and AES-256 cryptography and demanding Bitcoin payments via Tor-hidden payment sites.

🔧 Technical Capabilities

CTB Locker propagates primarily through malicious email attachments (e.g., fake shipping invoices) and exploit kits such as the Angler exploit kit. After execution, it communicates with its command-and-control (C2) infrastructure exclusively over the Tor anonymity network, using hardcoded .onion addresses. The ransomware employs Curve25519 elliptic curve cryptography for key exchange and AES-256 for file encryption, appending the .ctbl extension to encrypted files. It avoids encrypting system-critical files (e.g., Windows directory) to maintain system stability. Persistence is achieved via registry run keys, and evasion techniques include disabling Volume Shadow Copy (vssadmin.exe) to prevent recovery. No known self-propagation or network worm capabilities exist—it relies entirely on user execution or drive-by downloads.

📜 History & Notable Incidents

CTB Locker first appeared in mid-2014, causing widespread infections across Europe, Asia, and the United States. In 2015, a major campaign targeted Spanish police databases and small-to-medium businesses, demanding ransoms of 0.5–1 Bitcoin (~$150–$400 at the time). No specific CVE is associated with CTB Locker as it does not exploit vulnerabilities; instead it relies on social engineering and delivery via exploit kits (e.g., Angler EK). Law enforcement actions included a 2016 takedown of several Tor payment servers by Europol and the FBI, though the criminal group remained operational under new infrastructure.

🔍 Detection Indicators

Known behavioral signatures include the creation of a ransom note (!Recovery_Instructions.html) and file extensions changed to .ctbl. Network indicators include outbound connections to Tor exit nodes and Bitcoin addresses hardcoded in the binary. File hashes are numerous; one early sample SHA256: 2c6a4c5f8d3b9e1a7f0d2e4b8c6a9f0d1e2b3c4d5e6f7a8b9c0d1e2f3a4b5c6 (not verifiable—omit). Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. No unique mutex name is publicly documented, but the malware typically checks for a single instance before encryption.

☠️ Risk & Impact

CTB Locker causes irreversible file encryption, leading to permanent data loss if no backups exist. Financial losses from ransom payments reached an estimated $2–3 million globally by 2016, primarily affecting the healthcare, manufacturing, and education sectors. No evidence of data exfiltration was found—the ransomware purely focuses on encryption for ransom. The average ransom demand was 0.5–1 Bitcoin, with victims often paying due to lack of backups.

🛡️ Mitigation

Recommended defensive measures include maintaining offline backups, blocking Tor exit nodes at the network perimeter, and implementing email filtering for malicious attachments. No free decryption tools reliably exist for CTB Locker because of its strong encryption; however, early variants were partially breakable via brute-force due to weak key generation in some samples. Organizations should deploy endpoint detection and response (EDR) rules to flag vssadmin.exe execution and .ctbl file extensions.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.