HomeSecurityRansomware Warning: This Romantic Message May Hide Bad Surprises

Ransomware Warning: This Romantic Message May Hide Nasty Surprises

We draw attention to this romantic message because cybercriminals are exploiting Valentine's Day to distribute a productive form of ransomware.

GandCrab first appeared in January of last year and has become one of the most successful families of file-encrypting malware, with its creators regularly updating it with new tricks and techniques.

ransomware

Now the ransomware is being sent to potential victims in phishing emails with romantic subject lines coinciding with Valentine's Day in a campaign that has been analyzed by security researchers at Mimecast.

While campaigns related to holidays have traditionally focused on consumers, they are increasingly targeting business email accounts – providing attackers with a means to encrypt corporate networks and demanding larger ransoms than they could extract from individual victims.

The thematic sections used in this GandCrab campaign are related to romance. Some examples were: “I would like to confess what I feel for you”, “I wrote some things I think about you”, and “I am in love with you”.

The body of the email contains only a * symbol and is accompanied by an attachment – a zip file that contains a JavaScript file. The file name follows the same pattern in every malicious message – ‘Love_You_2018_’ followed by seven or eight random digits.

If the user chooses to extract and run the JavaScript, it will download and execute the GandCrab ransomware from a malicious URL embedded in the script.

Before the file is presented to the victim, they are asked to choose a language to view it – in English, Korean, or Chinese, which, according to researchers, shows the main targets of those behind GandCrab.

After that, the user is directed to the malicious note that explains that their computer has been encrypted and that they must pay a ransom in Bitcoin or DASH to recover their data.

Also the note states that the ransom will be doubled if they do not pay within seven days – and advice is offered on how to buy and use the cryptocurrency. The attackers even provide a live chat window to help victims pay the demanded ransom.

Researchers note that ransom payments vary depending on the victim, which indicates an aspect of planning behind the attacks – and that it is possible that the Valentine is not the work of the authors of GandCrab, a ransomware-as-a-service (RaaS) campaign itself.

GandCrab remains one of the most powerful ransomware threats around and is expected to continue to plague organizations for some time yet.

“It is likely that we will continue to see them update their versions”, The release of more versions will allow them to stay ahead of detection and continue offering it as RaaS to increase their profits “,said Mimecast to ZDNet.

However, organizations can avoid falling victim to it, by training users to watch out for strange or unexpected email – or by developing appropriate security software.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS