Showing posts with label Troldesh-Ransomware. Show all posts
Showing posts with label Troldesh-Ransomware. Show all posts

Tuesday, 11 August 2015

Ransomware Focuses On Russia And Ukraine


Makers of ransomware is not only aimed at English speakers, also should beware of Internet users in Russia and the Ukraine. Microsoft saw earlier this year named a ransomware variant appear Troldesh mainly in June was very active. The malware spreads through exploit kits, which infect Internet via, for example vulnerabilities in Adobe Flash Player.

Once active Troldesh encrypts files on the computer and then asks for a fee to decrypt them. Unlike other ransomware which victims must make the payment in bitcoin, the maker of Troldesh communicate via email with his victims. On the infected computer is left a text file with instructions. These instructions enable the victim via e-mail contact with the author should include.

In June, a researcher contacted the maker, then successfully on the ransom amount to barter . Eighty percent of infections Troldesh took place in Russia, followed by Ukraine with 9%. Microsoft advises victims to not pay the requested ransom for decryption, as there is no guarantee that the victims referred to regain access to their files.

Thursday, 4 June 2015

"Victim" Ransomware Receive Discounts Of Cybercriminal


Researchers have discovered a ransomware variant of which the author communicates via e-mail with victims and open to give off the ransom. The Troldesh-ransomware is spreading via email and ransomware encrypts like other kinds of files on the computer.

Remarkably, the ransomware also encrypts the file names. What is also striking is that Troldesh victims asked to contact via e-mail to decrypt the files and the payment method to use. Natalia Kolesova, researcher at security firm Check Point , decided an e-mail to the ransomware maker. She received within a few minutes an e-mail with instructions. To regain her files she had to send an encrypted file and pay 250 euros.

Then she asked in a subsequent email to discount, which ransomware maker had removed 15% of the amount. Eventually knows Kolesova get 50% off the ransom, which the author reports that the decryption key will not be given for free. "By the end of our correspondence I had received a 50% discount. Maybe if I had gone to negotiate even I could get a bigger discount," she noted. Recently, there was the creator of another ransomware copy which 'm vindicated and all infected computers decided to decrypt charge.

Virustotal Link