HomeinetSpora ransomware the new generation encrypts and steals

Spora ransomware the new generation encrypts and steals

Spora ransomware was recently upgraded and it seems that in addition to encrypting the victim's data, it also gained the ability to steal passwords and digital currencies from Bitcoin wallets.

By stealing credentials from their victims, criminals secure double profits, earning money from ransoms, but also from selling the stolen information to other criminals on underground forums.Spora ransomware

All of this is achieved with the help of a complex encryption process, which Spora has become known for. The encryption combines an AES key and an RSA public key to lock files on the victim's computer.

Additionally, the ransomware uses the Windows Crypto API to encrypt temporary data as well as Windows Management Instrumentation to delete backup copies of all encrypted files.

Essentially, Spora was a very powerful ransomware from the beginning, and now it has acquired the ability to steal data. The new variant was spotted by security researchers at Deep Instinct.

This version of Spora ransomware – which spread during a 48-hour campaign that began on August 20th – is spread by a phishing campaign that sends targets a Word document that claims to be an invoice.

To view the file's contents, the user is prompted to activate a Windows Script File, which allows the document to drop its malicious payload. This is the first time that Spora has been embedded in a document, according to the researchers.

Once executed, the malicious payload begins encrypting files on the computer, changing file extensions. Along with encryption, it searches for and deletes any backups on the computer before presenting the victim with a ransom note.

Researchers report that the latest version of Spora ransomware also collects users' browsing history, web credentials, and cookies, and has the ability to record keystrokes.

Spora ransomware: Protection

While the cryptography used by Spora is particularly strong, the phishing emails are somewhat obvious. A user trained in spotting fake emails will be able to avoid infection.

"Given that Spora's attack vector relies on user interaction, user awareness can play a significant role in stopping the threat. The rule of thumb is to pay close attention to messages, attachments, and avoid running or opening any content from an untrusted source," said Guy Propper, a researcher at Deep Instinct.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS