AVCrypt: New ransomware targeting antivirus software

A computer virus that seeks out and destroys antivirus software; that’s AVCrypt, a new ransomware variant which has recently been discovered.

The AVCrypt malware is designed to locate and delete PC antivirus software Windows Defender and Malwarebytes and then install ransomware onto an infected computer. By eliminating the computer’s antivirus programs before beginning the ransomware attack, AVCrypt effectively removes the local security protection that most PCs rely on to prevent such attacks, making this a very dangerous new malware strain.

AVCrypt was discovered by cyber-security researchers Lawrence Abrams, MalwareHunterTeam and Michael Gillespie. The researchers warned about their discovery in a Bleeping Computer blog post on Friday, March 23, saying that the new malware variant appears to be in an early stage of development and has probably not been deployed in cyber-attacks yet.

When AVCrypt is completed and used in an attack it will pose a formidable threat. The code is designed to be installed covertly, so it could be used as part of an email attack, delivered to the victim’s computer in the guise of an innocent looking email attachment.

The victim of an AVCrypt attack would be unaware of the malware deleting their local antivirus software; the first sign of anything being wrong would be a pop up on their screen threatening to delete all their files and demanding a ransom.

As well as eliminating antivirus software, the AVCrypt ransomware also prevents an infected computer from restarting so the victim of an attack wouldn’t even be able to shut down their machine to stop the attack.

The malware researchers who discovered AVCrypt on Friday warned that although this new ransomware is still not completed, it could be deployed in email attacks soon.


