HomeSecurityFake PayPal page spreads Nemty ransomware

Fake PayPal page spreads Nemty ransomware

ransomwareResearchers have discovered that hackers have created a fake pagethat supposedly offers an official . app PayPalIn reality, it aims to spread a new variant of the Nemty ransomware.

We've seen several variations of this ransomware lately . It seems that the hackers behind it are constantly looking for new ways to distribute it to unsuspecting users .

In the case of the fake Paypal page, hackers try to attract victims by promising a 3-5% refund on purchases made through the payment system.

There are many signs that someone might be scammed. For example, many browsers flag the page as dangerous. However, there are many unsuspecting users who may fall into the hackers’ trap and proceed to download and run the malicious software, which is known as “cashback.exe”.

The security researcher who discovered the new variant of Nemty ransomware and its distribution via the fake Paypal page is nao_sec. The researcher used the AnyRun to run the malware and observe the problems it creates on infected systems.

The researcher found that the ransomware takes about seven minutes to encrypt a victim's files. However, the time may vary depending on the system affected by the ransomware.

The good news is that the new variant is detected by most popular antivirus programs.

“Homoglyph” attack

If someone isn't paying close attention, the page will look authentic. The hackers have gone to great lengths to make the page as believable as possible.

To make it even more convincing, scammers use so-called “homograph domain name spoofing” for various links on the site, such as Help & Contact, Security, and more.

Security researcher Vitali Kremez analyzed this variant of Nemty ransomware and found that it is version 1.4.

The researcher noticed that the “isRU” check , which checks whether the infected computer is located in Russia , Ukraine, Belarus, Kazakhstan, or Tajikistan, has changed. In this particular ransomware variant, if the check result is positive, then the systems are not infected (their files are not encrypted).

Fake PayPal page spreads Nemty ransomware

However, hackers are also targeting other countries and they are at risk.

The Nemty ransomware has been making headlines recently. It has been circulating on hacking forums for some time now. However, the wider community learned about it in late August, when researcher Vitali Kremez discovered it and published his findings.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS