What Was CryptoLocker? The Ransomware That Gave the Files Back

The countdown was the innovation. Not the cryptography — a red window, a running clock, seventy-two hours, and a line saying that when it reached zero the key would be destroyed and nobody, including the people who wrote the program, could get the files back.

That was true. It was the first time it had reliably been true.

CryptoLocker is remembered as the beginning of modern ransomware, which is roughly right, and as the first ransomware, which is not. What it actually was is the first one that got the cryptography correct — and, because of that, the first one where paying reliably worked.

What was CryptoLocker?

CryptoLocker was a Windows ransomware family that first appeared on 5 September 2013.

It arrived two ways. Early on, as an email attachment dressed as a delivery notification from FedEx or UPS — a ZIP containing an executable with a double extension, so a machine with known file types hidden showed it as a PDF. That trick was thirteen years old by then; ILOVEYOU used it in 2000, and Windows still hid the extension by default.

Later, and more effectively, it was pushed directly by the Gameover ZeuS botnet onto machines that were already compromised — a banking trojan network monetising hosts it had already stolen everything obvious from.

Once running, it encrypted documents, spreadsheets, images and archives on local drives and every mapped network share, then displayed the ransom window.

What it actually got right

Every earlier generation of file-encrypting malware had a thread a researcher could pull.

The key was embedded in the binary, or derived from something predictable like the infection timestamp, or the author had written their own cipher and got it wrong, or the same key was reused across every victim so that one recovered key freed everybody. GPCode, through several versions between 2004 and 2008, was broken repeatedly for exactly these reasons — at one point by factoring an RSA key the author had made too small.

CryptoLocker did the boring, correct thing.

On execution it contacted a command server, which generated an RSA-2048 keypair unique to that victim and sent down only the public half. Each file was encrypted with a fresh AES-256 key, and that AES key was then encrypted with the victim's RSA public key and stored alongside the file.

This is standard hybrid encryption — the same construction as TLS, used correctly. It matters because it is often described as "RSA-2048 encrypted your files," which is wrong and makes the design sound more exotic than it was. RSA is slow and cannot encrypt bulk data; it was protecting the AES keys, which is what it is for.

The consequence is the whole story: the private key never touched the victim's machine. There was nothing on the disk to recover, no weakness to attack, no clever researcher trick available. The only copy was on a server in someone else's country.

The countdown, and the second chance

The ransom was around $300, or €300, or 2 BTC, payable by MoneyPak, Ukash, cashU or Bitcoin. As Bitcoin's price climbed through late 2013 the operators cut the BTC price to 0.5, which is a detail worth noticing: somebody was watching the exchange rate and repricing to keep the dollar figure stable. This was run as a business.

The clock ran for 72 hours, later extended to 100.

Enough people missed it — through holidays, through backups that turned out not to work, through simply not believing it — that the operators opened a second service afterwards, the CryptoLocker Decryption Service, which would sell you the same key later for 10 BTC instead of 2.

Which tells you that the deadline was never a technical constraint. The keys were not being destroyed at hour 73. The countdown was a pricing mechanism, and the "destroyed key" was a lie that made the first price look reasonable.

And if you paid, you got the files back

This is the part that reads strangely now, after a decade of ransomware that cannot or will not decrypt.

CryptoLocker's decryptor worked. Reliably. Researchers, incident responders and insurers all reported the same thing at the time.

It was not a courtesy. A decryptor that works is the only marketing a ransomware operation has. The moment word gets around that paying does nothing, the next victim does not pay, and the model collapses. Every operator since has faced the same incentive, and the ones that broke it — NotPetya most famously, which displayed a ransom note over a wiper with no decryption routine at all — were not running a business.

The numbers disagree by a factor of thirty

Ask how many victims paid and you get answers that are not in the same universe.

Dell SecureWorks, tracing the Bitcoin addresses on the blockchain, put the payment rate at roughly 1.3%.

A University of Kent survey of UK internet users, published in 2014, found that around 41% of self-identified CryptoLocker victims said they had paid.

Both were widely reported, often in the same article. They cannot both be describing the same thing.

The blockchain figure is measuring transactions, and it undercounts — not every payment route was Bitcoin, and address attribution is incomplete. The survey figure is self-reported by people who identified their own infection as CryptoLocker, which by 2014 was being used as a generic label for any ransomware, and it is a small sample answering a question about something embarrassing.

The totals have the same problem. The US Department of Justice, in the June 2014 indictment, put ransom payments at more than $27 million in the first two months. Blockchain-derived estimates from the same period land closer to single-digit millions.

The honest answer is that nobody knows, that the two methodologies are measuring different things, and that any article quoting one figure without the other is telling you less than it appears to.

Operation Tovar, and the keys going free

On 2 June 2014, an international operation announced the takedown of the Gameover ZeuS infrastructure — the FBI with Europol, the UK's National Crime Agency, and a long list of private firms and academics including Dell SecureWorks, CrowdStrike, Microsoft, Symantec, Trend Micro and Fox-IT. It was called Operation Tovar, and it took the peer-to-peer botnet that was CryptoLocker's main distribution channel.

The seizure also produced something nobody had planned for. Investigators came out of it holding the private key database.

In August 2014, Fox-IT and FireEye put it behind a free public portal called DecryptCryptoLocker. A victim uploaded one encrypted file, the service matched it against the recovered keys, and emailed back the private key and a decryption tool. No charge, no registration, no conditions.

Anyone still sitting on a locked disk — including people who had refused to pay on principle and lost everything for it — got their files back for nothing.

It was never the first ransomware

The claim turns up constantly and it is worth correcting, because the real lineage is longer and more interesting.

  • 1989 — the AIDS Trojan. Distributed on floppy disks mailed to attendees of a WHO AIDS conference, it encrypted filenames after 90 boots and demanded $189 sent to a PO box in Panama. Its author, Joseph Popp, was a Harvard-trained biologist. The encryption was symmetric and trivially reversed.
  • 2004–2008 — GPCode. Repeated attempts at real file encryption, repeatedly broken.
  • 2010 — WinLock. No encryption at all; it just locked the screen and demanded payment by premium SMS.
  • 2012 — Reveton. The "police trojan" that accused the user of a crime and demanded a fine, localised by country down to the correct national police logo.

Ransomware was twenty-four years old when CryptoLocker arrived. What was new in 2013 was the combination: correct public-key cryptography, so it could not be undone, and Bitcoin, so the money could be collected at scale without a mule network. Those two together are what made it an industry.

The man on the poster

Evgeniy Mikhailovich Bogachev — online as "slavik" and "lucky12345" — was indicted in June 2014 as the administrator of Gameover ZeuS. In February 2015 the FBI raised the reward for information leading to his arrest to $3 million, at the time the largest ever offered for a cybercriminal.

He was sanctioned by the US Treasury in December 2016. He is believed to live in Anapa, on the Russian coast. He has never been arrested, and the reward still stands.

Further reading

  • US Department of Justice — US Leads Multi-National Action Against Gameover Zeus Botnet and Cryptolocker Ransomware, 2 June 2014.
  • Dell SecureWorks — CryptoLocker Ransomware (Keith Jarvis), December 2013. The blockchain tracing.
  • Fox-IT and FireEye — the DecryptCryptoLocker announcement, August 2014.
  • Brian Krebs — Krebs on Security, the 2013–2014 CryptoLocker and Gameover ZeuS coverage.
  • Sood and Enbody, and the University of Kent Interdisciplinary Research Centre in Cyber Security survey, 2014, for the disputed payment rate.

EXHIBIT 0019 — CRYPTOLOCKER

We put it on a shirt. Not a padlock — a wall-mounted key cabinet, drawn as an engraving, both doors swung open, rows of identical keys on brass hooks, and a torn evidence seal hanging across the doors. One hook in the middle is empty, with a thread running down out of it.

The callouts are the incident: KEYS NEVER TOUCHED THE VICTIM, 2048-BIT RSA, SEIZED 2 JUNE 2014, THEN GIVEN AWAY FREE. Most people see an antique key cabinet. Anyone who was doing incident response in 2014 sees where the private keys ended up.

That's the whole idea.

View the CryptoLocker shirt — EXHIBIT 0019

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.