Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Tuesday, June 28, 2016

Bart Ransomware

Cyber criminals behind Dridex and Locky ransomware have started distributing a new file-encrypting software named as Bart. According to security company Proofpoint RockLoader malware is used to download Bart over HTTPS. Bart itself will encrypt the files without first connecting to a remote command and conquer (C&C) server.

Malware campaign has included sending messages with the subjects "Photos" containing malicious Javascript code file (e.g. PDF_123456789.js) zipped in as an attachment with name like "photos.zip", "image.zip", "Photos.zip", "photo.zip", "Photo.zip", or "picture.zip".

More information with details can be read from Proofpoint blog post here.

Friday, April 1, 2016

Petya Ransomware

Ransomware, a type malware that restricts access in computer system and requires a ransom for removing the restriction, is currently a big problem in digital world. New member to this family is Petya. Instead of encrypting just some file types Petya prevents user from accessing all the files on the hard drive by encrypting Master File Table. The user is asked to pay a ransom in order to get the hard drive decrypted.

Petya targets mostly business users as it is being distributed in spam emails that are targeting the human resources departments. First spam messages contained a Dropbox link to a malicious file. Since Dropbox removed the malicious archives the bad guys will likely use other way of distribution.


More information can be read in Kaspersky's blog here.

Monday, January 4, 2016

Ransom32 JavaScript-Based Ransomware

Security company Emsisoft warns about a new JavaScript-based ransomware. Fabian Wosar from Emsisoft says that a new ransomware family called Ransom32 is using the NW.js platform for infiltrating the victims' computers and encrypting their files with AES encryption.

"NW.js is essentially a framework that allows you to develop normal desktop applications for Windows, Linux and MacOS X using JavaScript. It is based upon the popular Node.js and Chromium projects. So while JavaScript is usually tightly sandboxed in your browser and can’t really touch the system it runs upon, NW.js allows for much more control and interaction with the underlying operating system, enabling JavaScript to do almost everything “normal” programming languages like C++ or Delphi can do. The benefit for the developer is that they can turn their web applications into normal desktop applications relatively easily. For normal desktop application developers it has the benefit that NW.js is able to run the same JavaScript on different platforms." At the moment only Windows appears to be targetted but at least in theory it could be packaged for Linux and Mac OS X too.

The best way to protect from ransomware is to have proper backups regularly made of all important files. These should be stored on a disconnected device since a lot of ransomware targets backups specifically. Good option is for example an external hard drive that is usually detached the system.


The Emsisoft blog post can be read here.

Tuesday, July 29, 2014

Onion Ransomware Under Closer Inspection

Ransomware has become one of the biggest type of malicious software. As its name says it asks affected user for a ransom. Fedor Sinitsyn from Kaspersky Lab writes about the latest one, Onion (aka Critoni), in his blog post.

The blog post can be read here.

Wednesday, October 16, 2013

Look Out For Nasty CryptoLocker

SophosLabs warns in their blog about a really nasty malware named as CryptoLocker. CryptoLocker encrypts files of specified file types on infected system and then asks user to pay a ransom in order to get files decrypted. Details about the infection and how to protect against it can be read from the SophosLabs blog post.

Bleeping Computer has an information guide and FAQ about CryptoLocker too. It can be viewed here.

Wednesday, September 7, 2011

Ransomware Posing As Microsoft

Security company Panda warns in their blog about a ransomware that tries to trick users to believe their Windows authenticity has failed. To get it fixed users are asked to pay 100€ by following given instructions. Naturally, nothing should be paid. Panda have published a code that can be used to deactivate the malware.

More information in PandaLabs blog.

Saturday, March 26, 2011

Another Return of GpCode

Kaspersky warns about a new version of nasty Gpcode ransomware type pest that encrypts files on infected system with a strong encryption and tries to make victim pay for getting those decrypted.

The program spreads via malicious websites as a drive by download. Kaspersky detect the pest as Trojan-Ransom.Win32.Gpcode.bn.

Due to heavy cryptography used, the encrypted files cannot be recovered making existing backups only possible solution (one good reason to have all important stuff always backed up on separate location).

More information can be read from Kaspersky blog.

Friday, January 8, 2010

Data Doctor 2010 - Combination Of Ransomware And Rogue

F-Secure introduces in their blog a pest that combines some elements of ransomware and rogueware. Trojan detected as DatCrypt encrypts Microsoft Office documents, video, music and image files and then shows user error message telling that files are corrupted. It advises user to download "recommended file repair software". This software detected, as Rogue:W32/DatDoc, lets user decrypt only one file unless a full version with price tag of $89.95, is bought.

Sunbelt has provided a decrypting tool to cure Data Doctor 2010 encrypted files.

Tuesday, December 1, 2009

Ransomware Locks Internet Access

Zarestel Ferrer, Senior Research Engineer in CA Internet Security, writes in company's blog about a nasty pest that takes internet access hostage.

CA detects the pest as Win32/RansomSMS.AH. It arrives bundled with uFast Software Manager named software and gets installed without end user's permission. When installed, it blocks internet access and only way to unlock is to send an SMS message to given number to get activation code. CA has released activation code generator that can be used to generate working code and unlock the access.

Screenshots and other info about the pest can be viewed here.

Friday, April 24, 2009

Ransomware Takes PC Hostage

Security company Panda writes in their blog about malicious software that takes PC hostage. If user doesn't pay the ransom, PC can't be used. According to Panda, Trj/Smslock.A works differently from most older ransomware. Traditionally, ransomware has for example encrypted important folders and files (e.g. Gpcode). In order to get a decryption key user has been asked to pay ransom to the criminals.

However, Trj/Smslock.A is different from those older ones. It takes whole PC hostage locking the access to the system. Instructions for unlocking are displayed on the screen. The instructions ask user to send an SMS text message with a series of numbers to some service number. In return, user receives a code that will open the lock.

Used language indicates the target victims are Russian speaking users.