
Ransomware them inaccessible to its victims. The hackers then demand a ransom in exchange for the key to decrypt the files. They often also give their victims a time limit, which if exceeded can lead to the data being deleted. Some ransomware attacks can also infect devices on your LAN. However, hackers are not only targeting home networks and devices, but also companies, hospitals and other services.
Ransomware is evolving more and more over time. In 2016, a ransomware called “Dharma” appeared. In fact, thanks to upgrades and additions, it still poses a significant threat. Trend Micro recently discovered a new ransomware variant that has infected Slovenian security company Eset and its Eset AV remover tool.
The attack is carried out via email, which appears to originate from Microsoft and the message states that the victim's computer is at risk. Then the email states that to keep the user safe, they must download a protection tool. The automatic extraction file is protected with the password “www.microsoft.com”, which is referenced in the email.
After downloading this security tool, a user interface of Eset AV remover appears. However, alongside the Eset tool, a secondary file with ransomware code is also executed. The user tries to install this tool, but in the background, the ransomware encrypts the victim's files. A file extension *.ETH is added to the affected files.
In the end, a ransomware message appears, informing the victim that their files are encrypted and they must pay to decrypt them, with instructions on how the user can contact the attackers in order to pay the ransom that was demanded.
As for the AV Eset remover, it doesn't matter whether this tool starts or installs successfully, it's just a trick to hide the ransomware's activity. The encryption process is independent of the installation status of this tool.
Eset AV remover is a tool for quickly and easily uninstalling antivirus software on a computer. In this case, “Dharma” and the Eset tool are running at the same time. The tool’s installer is waiting for user interaction, but “Dharma” is already encrypting files, so there is no way to uninstall the security software first and then start encrypting files.
