Krotten
Krotten is malware that targets Microsoft Windows devices, first detected in 2005. A form of ransomware, it acts as a trojan which modifies system registry files in affected devices, demanding payments in exchange for the restoration of the device's functionality.[1]
History
[edit]Krotten spread in 2005 as deceptive software available for download on a site hosted in Russia.[2] It was disguised as a program designed to generate codes to transfer funds into mobile phone accounts.[2] The site said that the program was developed by Ukrainian hackers and would work for "nearly all Ukrainian mobile service providers."[2] It functioned similarly to GPCode, in that upon running the program, the user's operating system would be locked down. An error message would be displayed on the screen offering a file that would remove Krotten from the device, in exchange for a sum equivalent to $5 USD.[3] The payment was requested to be sent via an email provided in the error message,[3] or in some iterations to be sent to the author's account under the Ukrainian cell provider Kyivstar.[4]
Krotten was first detected after Russian users began reporting the program to cybersecurity companies.[5] In November 2005, Kaspersky contacted the site's hosting company. The hosting company quickly shut down the site. However, Kaspersky warned that the program's author could make it available using another free web hosting service.[2]
According to Microsoft, Windows Defender has the capability to detected Krotten and prevent it from infecting devices.[6] Cybersecurity hobbyists have attempted to run Krotten and found that Windows Defender is able to detect the malware.[7] They have also found that Krotten is capable of running on Windows 10 and 11 (without malware protections enabled), but the email account to which the user is prompted to send ransom funds has recently been deleted.[7][8]
References
[edit]- ↑ Emm, David (2006-06-01). "Focus on trojans – holding data to ransom". Network Security. 2006 (6): 4–7. doi:10.1016/S1353-4858(06)70397-X. ISSN 1353-4858.
The most striking examples of this type of cyber-blackmail, carried out in the second half of 2005, are the trojans GpCode and Krotten. The former encrypts user data; whereas the Krotten trojan modifies the victim's PC rendering it unusable.
- 1 2 3 4 "Krotten source traced – for the moment". Securelist. 2005-11-09. Retrieved 2026-04-10.
- 1 2 "Your money or your system registry". Securelist. 2005-11-08. Retrieved 2026-04-10.
- ↑ Brandt, Andrew (2010-07-08). "Ransomware App Asks Victims to Pay a Phone Bill". Webroot Blog. Archived from the original on 2015-08-03. Retrieved 2026-04-10.
- ↑ "Malware Evolution: October – December 2005". Securelist. 2006-01-27. Retrieved 2026-04-10.
- ↑ "Trojan:Win32/Krotten.A threat description". Microsoft Security Intelligence. Retrieved 2026-04-10.
- 1 2 PC Place (2025-10-27). Will 2005 RANSOMWARE Run on Windows 11?. Retrieved 2026-04-10 – via YouTube.
- ↑ 10G Tech (2021-06-01). Ransomware.Krotten vs Windows 10. Retrieved 2026-04-11 – via YouTube.
{{cite AV media}}: CS1 maint: numeric names: authors list (link)