Showing posts with label Bitcoins. Show all posts
Showing posts with label Bitcoins. Show all posts

Wednesday, 23 September 2015

Ransomware: US County Pays Ransom



The IT department of Miami County in the US state of Ohio has on the advice of a security $ 700 paid to the creators of CryptoWall-ransomware so the county encrypted files recovered. Early September was faced by the county with an infection.

The administrative computer system of the communication was via e-mail gets infected by the ransomware said Troy Daily News. This center is also responsible for the 911 emergency service in the county, but the network of these became infected. The ransomware early $ 700 in bitcoins, which Miami County on the board finally paid advised by a security expert. According to the expert would be the retrieval of the encrypted document in this way be cheaper and faster, reports Dayton Daily News.

Tuesday, 22 September 2015

Ransomware Encrypts Servers Australian Sex Shop


Not only hospitals and writers are at risk to be affected by ransomware, also need to be careful sex shops. The owner of the oldest sex shop in the Australian state of Queensland last Friday hit by ransomware which are encrypted servers.

Only when three bitcoins were paid, what with the current exchange rate is about 600 euros, the encrypted data could be decrypted again. "I have to pay, I have no choice, these hackers can get all of our servers, including customer data," says owner Colin Edwards. "If we would try to gain access to our system, they have threatened to destroy it." How computers were infected, the shop owner does not know.

Edwards feels particularly let down by the police. Cops let him know nothing they could do and asked him to make online declaration. "We got an email back that they were very busy and could not tell if they contact," so let him across News Limited know. What customer data are exactly on the servers Edwards has not made ​​clear. Because of the infection, the online store of the sex shop offline.

Sunday, 23 August 2015

Subscribers Ashley Madison Extorted via E-mail



Several subscribers cheaters website Ashley Madison became the target of extortionists who threaten to inform their partner unless they pay an amount in bitcoin. Both American and New Zealand subscribers have received the email.

The email warns that the cost of a divorce lawyer if the partner comes behind the cheating, or anything revealing to have the data for consequences if someone is already in a separation procedure. It also warned of the reaction of family and friends as they discover that the person in question was active on Ashley Madison, so reporting CoinDesk and Stuff.

The extortionist then demands two bitcoins, what with the current exchange rate is 410 euros. How many subscribers have received the e-mail or run from the threat is unknown. Attackers managed last month to hack the website Ashley Madison this week and made ​​a part of the data publicly available. The media has already speculated that subscribers would be extorted possible.

Tuesday, 4 August 2015

American Town Pays Twice Ransom To Ransomware



A town in the US state of New York last year twice in a short time become a victim of ransomware. And twice it was decided to pay the ransom. It went together to the tune of $ 800. The infections were carried out in Ilion, which consists of 8,000 inhabitants.

The malware was spreading in both cases via e-mail attachments and encrypted both payroll and accounting systems, as the mayor opposite let NBC know. The infections, which occurred in January and May, were reported ( pdf ) by the Office of the State Comptroller. "These incidents are a wake-up call for local governments in the state," as late Comptroller Thomas DiNapoli know. "Although the amount of money was low and no vital information was leaked, this attack does show that lack of standard IT security taxpayers expense can hunt and functioning of cities and school districts can disrupt."

Canada

The problem of ransomware plays not only in the United States. Recently, also various systems of two Canadian towns hit by ransomware. When the infection in Mahone Bay were encrypted files back to 2007. An officer received an email supposedly a resume. The enclosed zip file appeared to be the CryptoWall-ransomware. Since the malware no important data encrypted was not proceeded to pay.

In the case of the infection in the Canadian Bridgewater would even talk of two ransomware specimens have been, namely CryptoWall and Crypto Locker, let the Chief Administrative Officer of the city across from CBC News to know. Also in this case would no important files are encrypted there and the ransom was not paid. To prevent a new infection is now controlled security against ransomware and henceforth be made ​​offline backups.

Wednesday, 17 June 2015

Banks worldwide extorted through DDoS attacks


A group of cyber criminals who extorted in the past, online casinos and gambling sites via DDoS attacks now focuses on leading banks, trading platforms and other financial institutions. Before warns security firm Arbor Networks. The group calls itself DD4BC criminals (DDoS for Bitcoin), and since last July active . In recent months, both the number and the scale of the attacks increased.

The company's website is first attacked shortly, so the group can determine the effectiveness of the DDoS attack. If it is successful there will be a mail in which a certain amount is required. Is not paid, then there is a severe and prolonged DDoS attack. In a warning to customers Arbor Networks describes 37 attacks / campaigns that carried the group. The actual number of victims is higher, because not all victims of the attacks on their website made ​​public, especially if they paid the amount requested.

The amount varies by asking the attackers attack. Some victims had to pay 100 bitcoin, what with the current exchange rate with 21,000 euro contract. Still, Arbor Networks advises companies not to pay the ransom. This will encourage criminals merely had to return to extort more money to continue their attacks. The group denies this and claims that the company only targets at once. Meanwhile there is also a reward of 110 bitcoin (23,000 euros) offered for information that the group can be unmasked.

Friday, 29 May 2015

"Dormant" Ransomware Makes Victims Worldwide


Main Locker Screen
This week, the world of computers with a new ransomware variant infected become infected systems which quietly and suddenly became active on 25 May. It is the locker-ransomware which like other kinds of ransomware specimens encrypts files on the system.

According Bleeping Computer is a large number of people worldwide affected by the malware. After the encryption users will see a notification that they have to pay 0.1 bitcoin. That comes with the current exchange rate equivalent to 22 euros. An amount that is one-tenth of what questions ransomware many other instances. In the warning that users get to see is further stated that they should not investigate Locker ransomware or remove, because the private key will be destroyed and the data is no longer decrypt.

Experts, however, that this is just a way to scare people so that they pay the amount requested. Besides the forum Bleeping Computer are also social news site Reddit been several reports of the victims appeared to have the amount paid. It is the low price of 22 euros given as a reason to watch or by paying the files are recoverable. Several victims have thereby know that after the pay could decrypt their files and so got back.

How Locker ransomware exactly spreads is not yet confirmed, but possibly it is a cracked version of Minecraft or sports streaming sites, although e-mail attachments and exploits are mentioned. The ransomware would just delete the Volume Shadow Copies on the C drive. This would be possible through the Volume Shadow Copies of other disks for files that have been encrypted there without paying retrieve .

Sunday, 19 April 2015

Ransomware Allows Victims To Recover From Error Files



A new ransomware variant that first appeared in late January and make the last month was increasingly active shows an error causing casualties without paying their files can be recovered. It is the Threat Finder ransomware which spreads through vulnerabilities in Java, Adobe Flash Player and Microsoft Silverlight that Internet users are not patched.

Once the ransomware encrypts which operates numerous files and asks here for 1.25 bitcoins, what with the current exchange rate is 259 euros. A researcher from Bleeping Computer discovered that the ransomware the Volume Shadow Copies are not removed from the computer, making it possible to access the files using the " Previous options can restore "of Windows, or a tool like Shadow Explorer .

Thursday, 9 April 2015

TorLocker-Ransomware By Mistake Decrypt Free


For several months, a new ransomware copy active TorLocker called, but by the fault of the author shows that stocks in more than 70% of cases are free to decrypt. TorLocker , also called "scraper", was the First discovered in late October last year.


Like other forms of crypto TorLocker ransomware encrypts all kinds of files on the computer and connected network drives for ransom. This keeps the ransomware account files that are larger and smaller than 512MB. Is a file larger than 512MB, then only the first 512MB of encrypted file. Also, all system restore points are removed and the ransomware sets a background with instructions how to decrypt the files. For this, the victim, a sum of $ 300 or more payments in bitcoins.

To encrypt TorLocker makes use of AES and RSA encryption. A bug in the implementation is the encryption in more than 70% of the cases to undo without victims must pay for this, says the Russian anti-virus firm Kaspersky Lab. The virus fighter developed a free tool that allows free access to the bulk of their encrypted files can decrypt. Last year also several ransomware variants discovered which were free by a programming error to decrypt.

Friday, 3 April 2015

Sleepless Nights After Infection By Ransomware


An Irish businesswoman was strange to watch when she was a seemingly innocent YouTube link on Facebook and clicked her computer suddenly was infected with ransomware. All files, both business and private, were encrypted. To access they had to pay two bitcoins, which corresponds to 450 euros. She saw eventually forced to purchase the bitcoins and to pay the ransom.

The whole process took two days and gave her sleepless nights, she leaves in front of the Belfast Telegraph know. "It was just a link on Facebook, and it seemed to me it on a YouTube video. I thought it was safe and had no doubts." The woman was especially afraid of losing her private pictures. In addition, the computer also contained all kinds of business data of its business.

Paying the bitcoins was no easy task, so let them know. "The person I bought them wanted to validate me. They had to show a photo ID and ID card. They had to know that I was a real person." After she had paid her files were decrypted after half an hour. It took more than a day before it was operational again. The woman describe the whole event as a very stressful situation. From examination of Threat Track among 250 US IT professionals of medium-sized companies shows that 30% are willing to pay in the event of ransomware.

Thursday, 26 March 2015

School District Shifting Exams Because Ransomware


A US school district has the math and English exams postponed after all kinds of files on the network were encrypted by ransomware. The Swedesboro-Woolwich School District in New Jersey consists of four primary schools, with a total of 2,000 students. The infection affected the entire school system, from e-mail communication and online learning tools to examinations conducted online.

Furthermore, would also files of employees are encrypted. Across New Jersey Online late headmaster Terry Van Zoeren know that teachers and students, because the systems were turned off, went to work as if it was "1981". For example, parents could receive e-mails with the numbers of pupils and other information and it was not possible to use the smart boards, as reports CBS. In a statement on its website allows the school district that the affected files mostly Word documents, Excel spreadsheets and PDF files of staff were.

Data of the student information system as well as other applications off-site should be preserved and are not affected by the ransomware. The encrypted files have been restored through a backup, as well as the servers where all the malware was removed. The school district is now working to get the e-mail and other systems in the air again.

According to Van Zoeren would ransomware to "500 bitcoins" ransom asked. An unprecedented sum for ransomware, which usually requires an amount of about $ 500. Possible that this is misunderstood or misinterpreted. How the school district became infected is not reported. In contrast, only explained in the statement how ransomware spreading in general.

Tuesday, 17 March 2015

Dozens Of Dutch Companies Pay Ransomware


In the first months of this year are already at least 28 Dutch companies have become the victim of crypto ransomware, which were encrypted terabytes of data on NAS systems. 25 companies finally decided the requested ransom, ranging from 300 euros to 1,000 euros to pay. According to the company are particularly SMEs who were victims of crypto ransomware.

Unlike many consumer which files are encrypted on computers, it's all the affected companies to NAS systems, including Synology, Qnap and Buffalo. These systems are used for the storage of large amounts of data. The ransomware encrypts would have between 1 and 20 terabytes of data to the entrepreneurs affected. Who subsequently received a warning that make decrypting the data is to be paid.

How the companies were infected, according to the recovery company difficult to determine. It could have happened through infected emails, but also visiting infected websites or downloading infected files is not excluded. In the case of Synology NAS systems were last year's target of ransomware that attackers were able to gain access to the system via an old leak.

Effects

The effects of the infections differed for each firm. There were various administrative agencies in which customer files and office documents were encrypted and the staff could not therefore continue to work on current orders. Also, there would have been graphic designers who, by all stood their data on the NAS server, threatened not to meet their deadline. The recovery company has also announced that several photographers were victims of the ransomware, with terabytes of footage of photo shoots and weddings were encrypted.

Most organizations who were the victims did not have enough to backups. "As a result, they were forced to pay the hackers the requested number of bitcoins. There have also organizations reported that there are sufficient backups were present and it was not necessary to pay the hackers for their data. The loss in these cases minimal, "says CEO Hamed Ghilav. In total, 25 companies agreed to pay the ransom and get their files back also. The three remaining companies had recent backups.

Still not Ghilav advises companies in principle to pay the ransom. "So the hackers get their way." The advice is therefore to make good backups. All companies that were affected and had paid the ransom in common that they did not have recent backups. According Ghilav stood still on the "to-do list" of entrepreneurs. "Here is our opinion too often gambled on '' that will not happen to us. '' Companies should really better go back up to in such cases to run on as little damage as possible."

Wednesday, 2 April 2014

Ransomware Crypto Defense allows decryption key behind computer victim

Ransomware Crypto Defense contains a crucial mistake: it allows the decryption key back to the computer of the victim.


Symantec analyzed Crypto Defense. The ransomware is part of the extended family of malware programs that encrypt files of victims until a ransom is paid. Crypto Defense uses Microsoft and Windows API to generate Encryption and decryption keys.

Key
Defense Crypto encrypts files using a 2048-bit RSA key. The secret key needed to de-crypt the files will be sent back to the server, the attacker until the ransom is paid again. Apparently the developers did not know that the secret key on the computer of the victim is in a directory containing application data. This key can decrypt the victim his data without the intervention of the cyber criminals. Itself, Unfortunately, the average user will not have enough knowledge to make this actually perform.

Success
Symantec estimates that have received, which shows the effectiveness of the scam. Cyber criminals within one month, more than $ 34,000 in bitcoins.
Symantec has blocked 11,000 Defense Crypto infection attempts in more than 100 countries. The majority of infection attempts were in the U.S., followed by Britain, Canada, Australia, Japan, India, Italy and the Netherlands.

MD5: f57d188c4667fab46208396af20badd2 (Virus Total Permalink)
         60f302b88160c27263c61c7e91dcb94e (Virus Total Permalink)