Home Malware Programs Ransomware Cyber Splitter Vbs Ransomware

Cyber Splitter Vbs Ransomware

Posted: September 23, 2016

Threat Metric

Threat Level: 10/10
Infected PCs: 12
First Seen: September 23, 2016
Last Seen: December 16, 2019
OS(es) Affected: Windows

The 'Cyber Splitter Vbs' Ransomware is a Trojan that encrypts your files to deny your access to them until you transfer money to ransom them. Like Trojans with similar payloads, the 'Cyber Splitter Vbs' Ransomware endangers the contents of any hard drive or server it can access, and may not restore your information, even if you do pay its ransom. Preemptive data protection methods and using appropriate anti-malware features can limit the impact of an infection or remove the 'Cyber Splitter Vbs' Ransomware before it can inflict any damage.

When Backdoor Trojan Authors Split Their Efforts Up into Extortion Campaigns

Cyber SpLiTTer is a name malware researchers have connected to ongoing Trojan campaigns specializing in backdoor attacks or remote access. Although that has been the primary focus of that threat brand name since early 2016, new Trojan samples point to the developer shifting towards a new kind of threat: file encryption Trojans. The 'Cyber Splitter Vbs' Ransomware is the current centerpiece of this new campaign, which encodes your data out of the hope of forcing you to pay ransom money.

The 'Cyber Splitter Vbs' Ransomware searches all accessible directories not critical to the operating system for easily-encrypted formats, such as DOC-based documents. These data types then are encrypted with an algorithm malware experts are identifying, although almost all Trojans of the same classification use a simple form of Advanced Encryption Standard (AKA AES). Once it's encrypted your data, blocking you from it, the 'Cyber Splitter Vbs' Ransomware loads a pop-up window.

The 'Cyber Splitter Vbs' Ransomware's pop-up uses a configurable field to provide information on where to send the ransom, which is at one Bitcoin (roughly six hundred USD) currently. The window doesn't include any automatic decryption feature, meaning that the threat actor expects the victim to make the payment and trust that he will restore their data afterward.

Getting the 'Cyber Splitter Vbs' Ransomware to Split from Your Hard Drives

Many file encryption Trojans use installers that circulate through e-mail spam, while lesser quantities also use other techniques. Secondary methods consist of exploit kits hosted on compromised sites or direct hacking attempts against a vulnerable server account. Using memory-constant anti-malware security protocols, scanning incoming files, and rotating through complex passwords are several top means of protecting your PC from a 'Cyber Splitter Vbs' Ransomware installer.

Since the 'Cyber Splitter Vbs' Ransomware doesn't have a current, free decryptor, any encrypted data may be tantamount to being deleted. Paying the ransom and hoping the 'Cyber Splitter Vbs' Ransomware's threat actor will reward you for the act is a less secure a method of preserving your files than keeping backups on cloud servers and removable drives significantly, both of which will negate the necessity of a decryptor.

Without your having the forethought to implement such common-sense security steps, even removing the 'Cyber Splitter Vbs' Ransomware through proper anti-malware tools may leave an aftermath of irrecoverable files on any PC, just like many, other Trojans.

Loading...