Γνωρίζετε τα Ransomware που κρυπτογραφούν τα αρχεία του θύματος και εκβιάζουν για λύτρα. Ωστόσο, οι ερευνητές ασφαλείας της Symantec, διαπίστωσαν ότι οι προγραμματιστές του κακόβουλου λογισμικού περνάνε μάλλον μια κρίση συνείδησης.
With the emergence of CryptoLocker, the infamous ransomware that encrypts victims' files, many Internet users have realized that if their computers become infected, it is very likely that they will never see their files again.
Symantec security researchers discovered a version of Trojan.Ransomscript that appears to be developed by malicious users who are fundamentally good people. Very deep, however.
After encrypting the files, the malicious program loads an additional file onto the computer with the extension (.OMG). The Readme.OMG is a text document that contains instructions on how victims can recover their data that is held hostage by the malicious software which has encrypted it. After the note that explains how the ransom will be delivered, there is a paragraph that states the following:
“P.S. Remember, we are not scammers. (!) We do not need your files. If you want, you can get a decrypter for free after one month. Just send a request immediately after infection. All your files will be fully restored. As your guarantee there are – decrypted samples and the positive comments from previous users.”
Thus, the scammers hope to earn revenue only from those who cannot wait a month to retrieve their files.
From a technical perspective, Trojan.Ransomcrypt.G is similar to other ransomware. However, according to Symantec experts, unlike the others, Ransomcrypt.G does not automate the delivery of encryption keys from the command and control server to the victim's computer.


