By now we have all heard of Ransomware malware that encrypts files or locks the victim’s computer and demands money to decrypt or unlock files and systems. Emsisoft has detected a new Ransomware malware called “ Linkup ”, and identifies it as “Trojan-Ransom.Win32.Linkup.” This malware does not lock the victim’s computer or encrypt their files. It blocks access to the Internet, modifies the computer’s DNS settings, and turns your computer into a Bitcoin mining robot.
Once the Linkup Trojan is installed on the victim's system, it creates a copy of itself and disables all selected Windows security features and services that will try to stop the infection. The DNS it adds to the infected system will only allow the malware to communicate with the internet.
It will then display a fake notification on the victim’s screen, which is supposed to be from the Council of Europe. The notification accuses the victim of “Child Pornography” and will allow access to the Internet if the victim pays a paltry 10 Euro cent fine.
It is still unconfirmed whether or not the malware will restore Internet access after paying the ransom, but it is likely a lie. To pay the ransom, you will need to use your credit card and submit your personal information. (Would you do that from an infected computer?)
In addition to blocking Internet access, Linkup also attempts to download and install other malicious programs. These will turn the victim's computer into a Bitcoin mining rig, connected to a botnet, so that they can combine the computing power of multiple infected computers and earn more Bitcoins.
Emsisoft says about the malware : “If your computer is infected, do not pay the ransom or provide any personal information. Install Emsisoft Anti-Malware to remove the malware and reset your system’s DNS settings.”

