HomeinetBreaking Bad ransomware not detected by VirusTotal

Breaking Bad ransomware is not detected by VirusTotal

Security firm Heimdal Security has uncovered a new ransomware campaign, which, up until now, is still not recognized by any of the 57 security products listed on Google's VirusTotal antivirus aggregator.Ransomware

The new ransomware spreads in Scandinavia, using spam emails, which come with an attached Word document. This file is trapped with a malicious macro that, when the document is opened, executes and downloads the ransomware onto the victim's computer.

When the ransomware downloads, it immediately encrypts the user's most important documents, and changes the file extensions to “.breaking_bad”.

Access to the encrypted files is impossible unless their owners pay the ransom.

The Word macro used by the ransomware has also been used by a Chinese hacking group that targeted Russian military bases.

The reason this technique is so popular among hackers is because it allows them to create malicious files that do not appear malicious at all.

This is probably also the reason why the ransomware is not detected by VirusTotal.virustotal

Word documents look like any other Word documents, and they do not contain any malicious payload, except for some instructions “to download a file from the Web” from a macro.

This file can be anything: an image, a CSS file, or malware. Thus the only way to protect against such threats is user education to not open any files on the Internet that come from unknown people, no matter what they promise.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS