
A new ransomware, discovered by Trend Micro and called Dharma, encrypts its victims' files by first installing an antivirus program.
Dharma, which is a strain of another dangerous malwareknown as Crysis, encrypts user files using Asymmetric Cryptography, a method in which the bits present in the file are encrypted.
Dharma Ransomware uses real Antivirus for malicious attacks
Dharma Ransomware's latest attempt is to mislead the user by sending an email titled 'MSC-ALERT-IMPORTANT!'. The message contains a warning, urging the user to click and download an older version of ESET Antivirus.
The email prompts the user to download and verify the antivirus using an attached password. The download file is a self-extracting one, named Defender.exe. It contains two files and the antivirus software installer.
The two malicious files are taskhost.exe and Defender_nt32_enu.exe. The first file activates the Dharma Ransomware itself as RANSOM.WIN32.DHARMA.THDAAAI.
The Ransomware tries to keep users busy with antivirus installations as it encrypts files in the background. The ESET Antivirus installer is completely real and works very well.
Furthermore, the installation process of ESET antivirus is in no way related to Dharma Ransomware. It should be noted that file encryption due to ransomware attacks and antivirus installation occur separately.
How does Dharma ransomware work?
- The user receives an email titled MSC-ALERT-IMPORTANT
- The email prompts the user to click and download the antivirus to which Dharma has attached it.
- User opens a password-protected file using the password attached in the email message
- ESET antivirus installation window appears to activate Defender.exe
- The Defender.exe file installs Taskhost.exe and Defender_nt32_enu.exe
- Taskhost.exe is the Dharma ransomware that presents itself as RANSOM.WIN32.DHARMA.THDAAAI
- Encrypts the file while the antivirus installation continues in the background
Current status of Ransomware attacks
In recent months, there has been a shift in ransomware attacks. Hackers have changed their tactics and are now disguising their ransomware as useful tools to trick users.
For example, ransomware called VxCrypt improves a user's computer's performance while encrypting their files. Some hackers are bundling the malware with torrent files of popular TV shows like Game of Thrones.
Although Ransomware changes, its basic steps remain the same – tricking users into downloading malicious files.
How to avoid it?
Users can protect themselves by following the golden steps of regularly backing up their files, restricting admin access, and keeping their systems up to date. However, most users can start by changing their password.
