HomeSecurityMalware blackmails unsuspecting victims

Malware blackmails unsuspecting victims

Malware demands ransom to allow access to user files, blackmailing unsuspecting victims.
Malware Malware Malware

ESET ’s research team in Canada has analyzed a widespread ransomware malware, known as TorrentLocker, which began spreading in early 2014 and targeted unsuspecting victims . The latest variant of the malware has infected at least 40,000 systems in recent months, primarily targeting European countries. The ESET research team has prepared an extensive report, which presents all the findings of the research and analysis of the malware’s behavior, as well as a related blog post on WeLiveSecurity.com.

ESET telemetry detects TorrentLocker as Win32/Filecoder.Dl. Its name comes from the registry key that the malware used to store configuration information under the fake name “Bit Torrent Application” when this filecoder began to evolve.

This ransomware family encrypts documents, images, and other files on a user’s device and demands a ransom to allow access to their files. Its typical signature is a ransom payment exclusively in crypto-currency – up to 4,081 Bitcoin (1,180 euros or 1,500 dollars). In recent campaigns, TorrentLocker has infected 40,000 systems and encrypted 280 million documents, targeting mainly European countries, but also users in Canada, Australia, and New Zealand. Of these cases, only 570 victims paid the ransom, which earned the perpetrators behind TorrentLocker $585,401 in Bitcoin.

ESET researchers have examined and analyzed seven different ways TorrentLocker spreads in their report. According to ESET telemetry data, the first traces of this malware date back to February 2014. The malware is constantly evolving, with its most advanced version being in operation since August 2014.

“We believe that the perpetrators behind TorrentLocker are the same as those behind the Hesperbot banking trojan family,” said Marc-Etienne M. Léveillé, a researcher at ESET in Canada. “In addition, with TorrentLocker, the perpetrators are responding to online reports by bypassing the Breach Indicators used to detect the malware and by changing the way AES (Advanced Encryption Standards) is used from Counter mode (CTR) to Cipher block chaining (CBC) mode after discovering a method for extracting the passwords.” This means that TorrentLocker victims can no longer recover all their documents by combining an encrypted file and its plain text to recover the password.

How does the infection spread? The victim receives a spam email with a malicious document and is led to open the attached file, usually unpaid invoices, package tracking updates or unpaid calls. The credibility of the email increases as it resembles the websites of businesses or the country of the victim's location. Upon opening the spam message, if the victim clicks on the link leading to the download page while not in one of the countries that have been attacked, they will be redirected to the Google search page. "To fool the victims, the perpetrators have inserted CAPTCHA images, creating a false sense of security," explains Léveillé.

More information about the TorrentLocker ransomware is available on ESET's security news website WeLiveSecurity.com. The first details about the investigation and the malware can be found on the blog. The detailed report is available here.

Author information

SecNews

SecNews

SecNews is a specialized website, which gives the opportunity to its visitors to be informed about the latest security news and trends in the IT industry.
SecNews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS