Showing posts with label Encrypting Files. Show all posts
Showing posts with label Encrypting Files. Show all posts

Friday, 6 November 2015

Ransomware Encrypts Offline Computers


In the case of a ransomware infection may help to disconnect from the Internet, so as to avoid encrypting files, but researchers have discovered a variant which also works with computers that are offline. It is ransomware aimed at Russian Internet users.

The ransomware encrypts files and changes the wallpaper of the computer. "Although most ransomware requires an Internet connection and a successful connection with the C & C servers Before encryption begins, this one does not require an Internet connection to encrypt files and show the hostage message," said security company Check Point.

According to the investigators, this means that there is no encryption key between the infected computer and attacker is exchanged, which prevents any ability to stop the attack. The ransomware demands a ransom amount of 290 euros on the first day of the infection. A day later, victims must already pay 360 euros for the decryption key. For the encryption there are two levels of RSA encryption. As mentioned, the ransomware locally the files without first encrypting may approximate the C & C server.

To decrypt the files, the attacker must first receive a file from the infected machine. It is not feasible to decrypt the RSA encryption without the private key of the attacker. This would, according to Check Point estimated two years to complete require a lot of computers. Paying the ransom is therefore the only way to recover the encrypted files, according to the company. Although the security company is only now reported on the ransomware shows that have existed since June last year and especially in Russia to be active.

Tuesday, 11 August 2015

Australians Pull Wallet Because Ransomware



Thousands of Australians have in recent months been victims of ransomware and also decided to pay the ransom, making the damage this year in the hundreds of thousands of dollars. The Australian Codings and Consumer Commission received 2500 complaints this year.

It is in this case for users and organizations whose computers became infected with ransomware. The ransomware encrypts files and then demands a price to decrypt them. The Commission estimates that this year 400,000 Australian dollars have been paid on account of ransomware, which is converted 365,000 euro. "But this is the tip of the iceberg," said Vice-President Delia Rickard opposite ABC .

Acquired throughout 2014 received the Commission's 2500 ransomware- em malware-related complaints, the damage amounted to more than $ 970,000. Converted this is 890,000 euros. According to the Commission ransomware have catastrophic consequences for businesses. By encrypting the files, companies can actually lose all their business and financial documents.

Wednesday, 25 March 2015

Danish Chiropractors Target Of Ransomware Attack


Danish chiropractors are the target of a highly targeted ransomware attack that attempts to encrypt all kinds of files for ransom. The attack begins with a perfect Danish drawn email, reports the Danish security firm CSIS . The IT security does not exclude that the message was written by a Dane. The email tries through social engineering open the receiver to let the included Dropbox link.

This link points to the kinds of ransomware that encrypts files on the computer. After encrypting a message appears on the screen that the files are encrypted and the user has 24 hours time to get his files, he or she will lose otherwise permanently.The malware also prevents the use of various Windows programs, such as Task Manager, Regedit and MSconfig. The ransomware has a keylogger to save keystrokes.

"We have decided to classify the attack as a major risk, even though that focuses on a specific group. This is mainly because of the level of social engineering that precedes the attack and the destructive code is attempted on the computer to install, "says Peter Kruse of CSIS. He notes that this type of attack is likely to be successful in many Danish organizations and therefore a threat to both companies and the authorities.

Fake Email Wehkamp Spreads Ransomware


Mail order company Wehkamp warns Internet users for an email that already goes around a few days and seems to come from the company, but in reality that is spreading ransomware encrypts files for ransom.According to the email, the recipient would have placed an order with Wehkamp.

It is the computer game Fifa 15 for the PlayStation 3. The message notes for more information on the order to the included zip annex which has an order number. The zip annex again contains an .exe file with an icon from Adobe that the malware appears to be. It is a variant of CTB Locker, which stands for Curve Tor Bitcoin. This ransomware resurfaced last year for the first time. Once users the .exe file to open the computer becomes infected and all kinds of files encrypted. Then users get some days to pay the ransom for decrypting the files.

The infected e-mails using the name of Wehkamp went last week all around, according to a warning from security researcher Mark Loman Twitter. Since then notify all kinds of Twitter users that they have the message received . Increasingly it appears to the so-called order of the computer. "There is indeed a phishing email around that does not come from us. You can best remove him immediately and not open!", says Wehkamp via Twitter.