
Thirteen years ago, computer users in the United States were returning to the office after the long Labor Day weekend when reports began surfacing of a new virus: Cryptolocker. The concept of ransomware wasn’t new — it had started back in 1989 with the AIDS Trojan — but widespread awareness of its implications was just beginning.
Social engineering drives rapid spread
According to early news reports, Cryptolocker was first spread via spam carrying a ZIP file. The ZIP file was purported to contain information about a customer complaint (good ol’ social engineering). When word got out about that tactic, future emails included a message about a problematic check transaction, with a link to “fix” it. Instead, clicking the link downloaded a Trojan horse (Gameover Zeus), which attached the infected computer to a botnet and installed Cryptolocker. Other infected emails masqueraded as UPS or FedEx alerts.
The cost of Cryptolocker
Once installed, Cryptolocker encrypted the user’s files until a ransom was paid in bitcoin or another virtual currency. By mid-December 2013, security experts estimated up to 250,000 computers had been infected, with half in the United States. The U.S. Department of Justice later reported that an estimated $27 million in ransom payments had been made.
In June 2014, through the work of Operation Tovar, U.S. law enforcement officials announced that the results of a multinational sting had taken down key servers in the spread of Cryptolocker, as well as disrupted Gameover Zeus. The Justice Department identified Russian Evgeniy Mikhailovich Bogachev as the suspected architect behind the malware. Bogachev is still at large.
Did you enjoy this installation of SmarterMSP’s Tech Time Warp? Check out others here.
Photo: Gorodenkoff / Shutterstock
This post originally appeared on Smarter MSP.

