April 23, 2019 By David Bisson 2 min read

Security researchers discovered that a new DLL CryptoMix ransomware variant is reportedly using Windows Remote Desktop Services (RDS) to install itself on unsuspecting users’ machines.

Bleeping Computer first learned about the ransomware when someone revealed in its forums that they had suffered an infection. The user went on to note how those responsible for the attack had exploited their machine’s publicly exposed RDS to infiltrate their computer and install the DLL CryptoMix variant. As part of this infection chain, the attackers also apparently enabled the computer’s default admin account and changed its password.

The sample analyzed by Bleeping Computer modified each file it encrypted by appending the .DLL extension to its file name. It then saved a ransom note to the compromised machine informing the victim to send their infection ID number to multiple email addresses, such as dllteam@protonmail[dot]com, dllpc@mail[dot]com and others. The attackers promised in their note that they would send over payment instructions immediately upon hearing from the victim at all of these email addresses.

The Changing Face of CryptoMix

At the beginning of the year, Coveware observed a similar CryptoMix attack that claimed all ransom payments would go to a fictitious children’s charity. And in March, Bleeping Computer spotted a variant using .CLOP or .CIOP extensions as it apparently shifted its focus to target entire networks instead of individual computers.

This attack also comes amid the growing costs associated with a ransomware attack. In April, Coveware observed that the average payment associated with ransomware in Q1 2019 had risen to $12,762 — an 89 percent increase from Q4 2018’s average of $6,733.

How to Defend Against DLL CryptoMix

Security professionals can help defend their organizations against a DLL CryptoMix infection by implementing a robust data backup strategy and vetting backup policies, including regular testing to make sure the organization can obtain viable backups. Security teams should also use an endpoint management solution to ensure all endpoints’ software is up to date and to acquire greater visibility into the production environment.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today