"CTB-Locker ransomware operators are taking advantage of a feature introduced to Bitcoin in 2014, when the Bitcoin protocol started allowing for small blocks of arbitrary text (metadata) to be included in the OP_RETURN field. The feature made blockchains applicable to fields unrelated to Bitcoin, and cybercriminals are abusing it, it seems.
According to Sucuri researchers, the ransomware operators create a new Bitcoin wallet with a unique address for each encrypted website, and they publish the address to the ransom demand page. When the victim pays the ransom, the hackers check the transferred sum and the wallet’s blockchain is appended with a new transaction whose OP_RETURN field contains the decryption key.
The OP_RETURN transaction is validated and propagated through distributed nodes of the Bitcoin system, and it also becomes visible in services that provide information on blockchains. This is why cybercriminals advise victims to track their transactions on the blockhain.info site."
http://www.securityweek.com/ransomware- ... SS+Feed%29