Cryptorbit: The Ransomware That Skipped the Hard Part and Still Got Paid

Key takeaways
- Cryptorbit, also called HowDecrypt, appeared in December 2013 and demanded about $500 in bitcoin via Tor, doubling the price if victims waited more than 96 hours; later versions raised demands as high as 2 bitcoins.
- Unlike CryptoLocker or GPcode, Cryptorbit did not fully encrypt files: it corrupted only the first 512 to 1024 bytes of each file header, making files unreadable while avoiding the cost and complexity of real cryptography.
- The article contrasts Cryptorbit with CryptoLocker, which launched on September 5, 2013, used genuine RSA-2048 and AES encryption, asked roughly $400, infected an estimated 250,000 computers, and was disrupted by Operation Tovar in June 2014; a Dutch security firm later recovered its private keys for free decryption.
- Cryptorbit also installed cryptocurrency mining software on infected machines, fewer than half of antivirus programs detected it at the time, and it spread through fake Flash Player updates and rogue antivirus pop-ups.
- Because Cryptorbit damaged headers instead of encrypting full file contents, some victims could recover files by rebuilding headers for certain file types, making the ransom demand at least partly a bluff.
- The piece cites Arizona State University researchers Kevin Liao, Ronghua Zhao, Adam Doupé, and Gail-Joon Ahn, who traced CryptoLocker to 968 bitcoin addresses and 795 completed ransoms, with most payments tied to the United States, Great Britain, and Australia.
How a handful of corrupted bytes and a bitcoin address turned ransomware into a business anyone could copy.
An Adaptive Security series on the ransomware attacks that shaped modern cyber defense. Hub: A History of Notable Ransomware Attacks. Previously: GPcode.
By December 2013, criminals building ransomware faced an unusual choice. They could spend months building strong cryptography the way GPcode’s authors had. Or they could skip that step and see if anyone noticed. A strain called Cryptorbit, also known as HowDecrypt, chose the shortcut. It barely touched the files it claimed to lock, and victims paid anyway.
From a victim’s chair, the distinction barely mattered. A photo, a spreadsheet, or a client file that will not open reads the same whether the damage came from world-class encryption or a few corrupted bytes. Cryptorbit understood that the fear did the selling, not the engineering behind it.
Cryptorbit built on a business that already existed. Three months earlier, a strain called CryptoLocker had shown that the market was there. CryptoLocker appeared on September 5, 2013, encrypted files with genuine RSA-2048 and AES cryptography, and demanded roughly 400 dollars. It infected an estimated 250,000 computers before an operation called Tovar disrupted the botnet distributing it, in June 2014. A Dutch security firm recovered the private keys the attackers had used and gave victims a way to unlock their files for free.
Cryptorbit arrived that December, riding the wave CryptoLocker had proven possible. Victims found two files waiting in their folders, HowDecrypt.txt and HowDecrypt.gif, pointing them to a payment page hidden on the Tor network. The price was roughly 500 dollars in bitcoin, and it doubled if a victim waited more than 96 hours to pay.
The Shortcut in the Fine Print
The difference between Cryptorbit and the strain it copied was in the fine print. Instead of encrypting a file the way GPcode or CryptoLocker did, Cryptorbit corrupted the first 512 to 1024 bytes of each file’s header. That was enough to make a document, spreadsheet, or photo unreadable to the programs meant to open it, without the cost or complexity of full encryption.Ross Anderson was a professor of security engineering at the University of Cambridge who spent much of his career studying exactly this kind of trade-off. Writing with economist Tyler Moore in a widely cited paper on the economics of information security, he put it plainly: "Security failure is caused at least as often by bad incentives as by bad design." Cryptorbit's authors used that same logic to their advantage. Building strong encryption costs time and skill. Corrupting a file's header costs almost nothing. Victims could not tell the difference from the ransom note, and the ransom got paid either way.
The group behind it also installed cryptocurrency mining software on infected machines, collecting a second stream of revenue while the ransom demand sat unpaid. Fewer than half of antivirus programs caught it at the time. Distribution ran through fake Flash Player update prompts and rogue antivirus pop-ups, the same low-cost tricks that had been working on the internet for years.
The shortcut had one upside for victims willing to look for it. Corrupting a file header is not the same as encrypting the data inside it, and for some file types, data recovery specialists could rebuild a damaged header well enough to restore the file without paying anything. The fix was inconsistent and depended heavily on the file type involved, but it meant Cryptorbit’s ransom demand was, for at least some victims, a bluff worth calling.
By the spring of 2014, Cryptorbit’s campaign was still running. Later versions of the ransom demand climbed as high as two bitcoins, evidence the scheme kept working for months after its December 2013 debut. Cryptorbit was not the only strain to follow this path. CryptoDefense arrived within months of CryptoLocker's debut using genuine RSA-2048 encryption, only for researchers to discover its authors had forgotten to delete the private key from infected machines, undoing months of careful design with one careless mistake. CryptoWall, built by the same authors after that flaw became public, picked up where CryptoDefense left off later that same year. Every strain took its own kind of shortcut, whether that meant skipping the cryptography like Cryptorbit or botching the operational discipline around it like CryptoDefense.
What the Shortcut Proved
No one ever mapped Cryptorbit’s own bitcoin trail the way researchers later did for CryptoLocker, the strain it rode in on. That CryptoLocker research still describes the market Cryptorbit was chasing. Researchers who traced CryptoLocker’s bitcoin payments found 968 addresses and 795 completed ransoms in just a few months of activity. Kevin Liao, Ronghua Zhao, Adam Doupé, and Gail-Joon Ahn, computer scientists at Arizona State University, concluded that "the current understanding of ransomware and the role of Bitcoin in online crime is insufficient for the development of effective countermeasures."
Their analysis traced most of that money to the United States, Great Britain, and Australia, exactly the English-speaking, high-income markets these campaigns were built to target. Bitcoin gave criminals a payment system that worked the same way everywhere, and that was all the technical skill this business ever required.Ransomware stayed profitable because so little stood in its way. Dr. Josephine Wolff, associate professor of cybersecurity policy at The Fletcher School at Tufts University and a faculty associate at Harvard's Berkman Klein Center, has pointed to where that needs to change. "How do we make this a less profitable enterprise for criminals? How do we cut down on ransom payments?" she said.
Cryptorbit ran on two things: a bitcoin address and a group of people willing to click on a fake update. No cryptographer. No botnet. No new idea required. That combination built the copycat wave that turned ransomware from a rare technical feat into a repeatable business, one every strain since, including WannaCry and GandCrab, has scaled in its own way. The technology wrapped around that business keeps changing. Cryptorbit got its start the same way a lot of ransomware still does: someone trusted a message they should not have. Adaptive Security studies this history because that moment is still where a large share of these attacks start.
Next in this series: WannaCry, the worm that took this business global in a single day.
Get started with Adaptive Security
Get started