A new malware cocktail steals passwords before they are encrypted by Windows.
A number of compromised sites are redirecting their visitors to websites containing the infamous Angler exploit kit, which helps hackers carry out drive-by attacks relatively easily.
This type of attack is particularly insidious, as it can be done automatically and without the user's knowledge. Once the Angler exploit kit finds a vulnerable application, such as Flash, it automatically serves up the required malware.
According to a publication by Heimdal Security, a widely used data-stealing software known as Pony “systematically collects all used usernames and passwords from the infected system” and sends them to servers controlled by hackers.
This allows malicious users to gain access to websites, e-commerce sites, and even corporate applications, from which they could steal additional data.
Immediately after the Angler exploit kit, it serves up the widely used CryptoWall 4 ransomware, which locks all of the victim's files until the ransom demanded by the malicious users is paid.
The ransomware is being served to thousands of users every week, and is generating $18 million in profits for the crooks, according to FBI estimates. Other data shows the Cryptowall family has so far generated $325 million in Bitcoin for those serving it.
One of the best ways to mitigate the attack is to keep all your applications up to date. You should also regularly back up your files to an external hard drive.
Meanwhile, BitDefender has released a “vaccine” that can prevent Cryptowall ransomware infections and is making it available for free.
Bitdefender CryptoWall Vaccine
