Crocodile Smile 勒索软件将劫持您的数据


在对新文件样本进行调查时,我们的研究人员发现了 Crocodile Smile 勒索软件。该恶意软件的工作原理是加密数据,然后要求付费才能解密。

在我们的测试机上运行 Crocodile Smile 样本后,它立即启动了加密过程。受影响文件的文件名被修改为“.CrocodileSmile”扩展名;例如,“1.jpg”变为“1.jpg.CrocodileSmile”,“2.png”变为“2.png.CrocodileSmile”,所有加密文件都是如此。

加密过程完成后,Crocodile Smile 改变了桌面壁纸,并生成了一张标有“READ_SOLUTION.txt”的勒索信。

勒索信的内容表明 Crocodile Smile 主要针对大型组织而非个人用户。从勒索信中的一行字可以看出,受害者很可能位于欧洲,其中提到遵守欧洲数据保护法规,表明该组织致力于向受害者通报入侵情况并提供援助。

勒索信中传达的信息告知受害者,他们的文件已被加密,敏感数据已被泄露。他们被要求支付 20.6 BTC(比特币加密货币)以获取解密密钥,并防止攻击者泄露被盗数据。截至撰写本文时,这笔金额约为 140 万美元,因此很明显勒索软件针对的是企业和组织,而不是家庭用户。



If you are opportune to see this message right now, that means your data security has been compromised !!!

You have been hit hard by a sophisticated Ransomware Attack by CROCODILE SMILE, LOL. This Attack is known as OPERATION FLUSH.

All your critical and confidential files, including private documents, photos, databases, and other important informations, have been encrypted, leaked, and transferred to our servers.

In accordance with European data protection regulations, we are reaching out to inform you of this breach and to offer assistance in recovering your encrypted files.

We acknowledge the gravity of the situation and are fully dedicated to swiftly delivering a solution. Our priority is to safeguard your organization's reputation and ensure the confidentiality of your files and documents remains intact, free from any leaks or compromises.

To initiate the decryption process and retrieve your files, please follow these official steps:

1) Contact our designated communication channel via Telegram ID: CrocodileSmile

2) Make the necessary arrangements to obtain 20.6 Bitcoin, as payment for the decryption service. Please note that decryption can only be completed upon receipt of payment in Bitcoins.

3) Upon successful payment, we will provide you with the decryption key required to swiftly decrypt all affected files. We assure you that compliance with these instructions is crucial for the recovery of your data.

We urge you to act swiftly to mitigate further data loss and restore the integrity of your information assets. Should you require any clarification or assistance, do not hesitate to contact us through the designated communication channel.









April 10, 2024

Cyclonis Backup Details & Terms

免费的基本 Cyclonis 备份计划为您提供 2 GB 的云存储空间和完整的功能!无需信用卡。需要更多存储空间?立即购买更大的 Cyclonis 备份计划!要详细了解我们的政策和定价,请参阅服务条款隐私政策折扣条款购买页面。如果您想卸载应用程序,请访问卸载说明页面。

Cyclonis Password Manager Details & Terms

免费试用:30 天一次性优惠!免费试用不需要信用卡。免费试用期间的全部功能。 (免费试用后的完整功能需要订阅购买。)要了解有关我们的政策和定价的更多信息,请参阅EULA隐私政策折扣条款购买页面。如果您想卸载应用程序,请访问卸载说明页面。