Security advisories

Ransomware Variant (CryptoFortress) Advisory

February 26, 2019 | 4 MINS READ

Speak With A Security Expert Now

TALK TO AN EXPERT

We have discovered a new ransomware (malware) variant referenced as CryptoFortress in the wild and would like to provide additional information as to what we have discovered at this time. Please find below a more detailed investigation into the behavior of and mitigation methods applicable to CryptoFortress ransomware.

What We Know

Behavior of CryptoFortress:

Additional Information:

eSentire Defenses

eSentire features that help protect you:

Further Protection

How to further protect yourself from this emerging threat:

User awareness (Infections are occurring from users clicking on a malicious payload that is being delivered via spam email attachments).

eSentire recommends blocking .zip and .exe file extensions on your SMTP server.

Back up important data offline.

If you are running Windows 7 Ultimate/Enterprise or Windows 8 Pro/Enterprise you have the ability to use AppLocker. AppLocker is able to defend against CryptoFortress infections because it can require all programs to be signed by a legitimate software publisher.

Alternatively, AppLocker has the ability to whitelist folders.

View Most Recent Advisories