HomeSecurityChaos ransomware: Targets players via fake Minecraft alt lists

Chaos ransomware: Targets players via fake Minecraft alt lists

The Chaos Ransomware gang encrypts players' Windows devices via fake Minecraft alt lists promoted on gaming forums.

Minecraft is a highly popular sandbox video game currently played by over 140 million people and according to Nintendo's sales figures, it is a top-selling title in Japan.

See also: Researchers provided decryption tool to victims of BlackMatter ransomware

Chaos ransomware: Targets players via fake Minecraft alt lists

See also: BillQuick Web Suite Bug: Used to develop ransomware

Covered as a text file “alt list”

According to researchers at FortiGuard, a variant of the Chaos ransomware recently discovered is being temporarily distributed in Japan, encrypting Minecraft players' files and dropping ransom notes.

The delayer used by threat actors is text files «alt list» that are supposed to contain stolen Minecraft account credentials, but in reality, it is executable ransomware Chaos.

Minecraft players who want to troll other players without the risk of their accounts being banned sometimes use ‘alt’ lists to find stolen accounts they can use for prohibited offenses.

Due to their popularity, alt lists are always in demand and are usually shared for free or via automated account generators that provide the community «spare» accounts.

Chaos ransomware

The Chaos Ransomware

During victim encryption, the Chaos ransomware will add four random characters or digits as an extension to encrypted files.

The ransomware will «drop» and a ransom note named «ReadMe.txt», where the threatening actors demand 2.000 yen (~ 17,56 $) on prepaid cards.

Chaos ransomware

See also: Ransomware attack on Norsk Hydro: The culprits were arrested!

A devastating infection

This particular variant of Chaos Ransomware is configured to search infected systems for different types of files smaller than 2ΜΒ and encrypt them.

However, if the file is larger than 2 MB, it will insert random bytes into the files, rendering them unrecoverable even if the ransom is paid.

Due to the destructive nature of the attack, those who pay the ransom can recover only smaller files.

The reason for this functionality is unclear and may be due to poor coding, incorrect configuration , or intentional corruption of players' files.

In this campaign, threat actors promote text files to create a false sense of security, but in the end they swap them for executables.

Users should be suspicious and not execute files they download from the internet, unless they trust the website and have scanned it with a tool such as VirusTotal.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS