CryptoLocker: 250K infections in 100 days nets $300,000 or does it?

Updated happygeek 2 Tallied Votes 558 Views Share

According to Dell SecureWorks Counter Threat Unit (CTU) security researcher , the CryptoLocker ransomware that has been written about so much of late has infected as many as 250,000 computers during the first 100 days of distribution (staring on the 5th of September, 2013). What's more, Jarvis estimates, based upon independent research, that owners of at least 0.4% of the infected machines will have paid the ransom demanded in order to unlock their data. Some pretty simple maths says that the $300 ransom multiplied by 1000 users equals a net haul of $300,000. Right? Well, maybe not.

Although it does seem likely that CryptoLocker remains the work of a single criminal gang, and security experts suggest it is operating out of either the Russian Federation or former Eastern Bloc states, the total ransom generated so far is open to some doubt. I'm not doubting that the infection rate is correct, and Jarvis himself admits that the 0.4% number of folk coughing up the cash is very much a minimum figure and likely to be much higher in reality, I do think that even so the total profit if going to be much, much greater. Why so? Well, I would imagine that you can up the number of people paying for a decryption key from that very low 0.4% to at least 1% which in itself still seems on the low side for such a well co-ordinated and executed attack as this. But hey, let's side with caution and say it is 1%, that immediately turns $300,000 into $750,000: or it would if we were talking about cash here.

Ah, yes, now this is where the numbers start to really get interesting because the CryptoLocker ransom isn't being paid in cash but rather in bitcoins. The thing about Bitcoin as a virtual currency is that it virtually knows no bounds as far as exchange rate volatility is concerned. Indeed, initially the bad guys were asking for a 2 bitcoin ransom, which at the time worked out to about $300. Then Bitcoin went through the roof (more than $800 for one bitcoin), and the gang realised people were much less likely to cough up $1,500 or thereabouts to release their data. So the ransom dropped to 0.5 bitcoin instead, which at todays rates would be about $375.

The point being, that if the gang got a bunch of people paying at the original 2 bitcoin rate, and let's say proportionately more paying at the 0.5 bitcoin rate, that's still a lot of coin! I would further assume that, given how technically advanced CryptoLocker is as a piece of ransomware, that this gang are not technically inept and understand the mysteries of the Bitcoin markets. In which case I doubt they were cashing in immediately, making their haul of bitcoins worth a lot more than the original guesstimate of $300,000 and even that revised $750,000 figure would suggest.

If these guys have not made more than a million dollars out of CryptoLocker then you can call me Jan. However, seeing as I am not a Dutchman's Uncle, I will stick my neck out and say that I imagine the CryptoLocker gang have already cashed in at least half a million and are watching the Bitcoin market for the right time to cash out the remainder of their haul. At which point, they will probably have made in excess of $1.5m in my never humble opinion.

Dani AI

Generated

made the key observation: treating an infection count times a sticker ransom as the gang’s “take” misses several major variables. Bitcoin-denominated extortion adds exchange-rate risk, criminals change demands and collection windows, and a large share of on‑chain receipts can be hidden or converted before anyone can call it a cashout. Empirical work shows that careful blockchain measurement gives lower-bound figures that often differ sharply from headline arithmetic. Liao et al., eCrime 2016, and a broader follow-up study in the Journal of Cybersecurity, explain these methods and limitations. (see below).

How investigators and researchers reconcile those moving parts: 1) start from seed Bitcoin addresses (from ransom notes, forum posts, victim reports); 2) expand the cluster using co-spend/multi-input heuristics; 3) time-filter transactions to the campaign window; 4) classify collector vs. payment addresses; and 5) follow outgoing flows to mixers or exchanges. That process produces defensible lower bounds but cannot fully reveal fiat conversions where off‑chain steps or mixing are used. The academic work also documents links between early ransom clusters and services such as mixing services and exchanges. Liao et al., eCrime 2016.

Operational context matters: international law‑enforcement disruption of the botnet infrastructure significantly changed the campaign’s lifespan and receipts — the U.S. DOJ/FBI public releases on the multinational operation explain how sinkholing and server seizures interrupted both credential‑theft and ransom operations. That intervention is a material reason why raw infection counts don’t map directly to long‑term profits. .

Practical checklist for anyone wanting a rigorous estimate: preserve the ransom note and wallet strings; collect full blockchain tx history for the period; apply clustering and time filters; identify downstream deposits to known exchanges/mixers; and, where appropriate, coordinate with law enforcement to request exchange KYC. For reproducible, peer‑reviewed methods and discussion of limits see the cited analyses in eCrime and the Journal of Cybersecurity.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.