HomeSecurityFake adult websites push data wipers disguised as ransomware

Fake adult websites push data wipers disguised as ransomware

Malicious adult content websites are reportedly promoting fake ransomware which, in reality, acts as a data wiper that silently attempts to delete almost all data from a device.

See also: BlackByte ransomware: Uses the new BYOVD technique

wiper

While it is unclear how hackers promote these sites, it appears that some are using names that refer to nude photos, such as nude-girlss.mywire[.]org, sexyphotos.kozow[.]com, and sexy-photo[ .]online.

According to security firm Cyble, which first reported the phenomenon, the websites automatically prompt users to download an executable file named SexyPhotos.JPG.exe, which is supposed to be a JPG image.

So since Windows disables file extensions by default, the user simply sees a file named SexyPhotos.JPG in their “Downloads” folder and would likely open it immediately, thinking it was an image.

Upon startup, the fake ransomware-data wiper drops four executable files (del.exe, open.exe, windll.exe, and windowss.exe) and a batch file (avtstart.bat) into the %temp% and then executes them.

The batch file guarantees persistence by copying all four executable files to the Windows startup folder.

Then, “windowss.exe” is executed to drop three additional files, including “windows.bat,” which performs the rename.

See also: Avast: Decryption tool for Hades ransomware
ransomware

The result is that all files are renamed to a generic name, such as “Lock_6.fille.” So, while the contents of these files are not modified or encrypted, victims have no way of understanding their original names.

Ransom notes are dropped by “windll.exe” in various locations with the name “Readme.txt”.

The note demands payment of $300 in Bitcoin within three days, threatening to double to $600 if the deadline is extended to seven days. However, if that time frame passes, all files will be permanently deleted.

In reality, this fake ransomware has not stolen data and it is unlikely that the creator of the malicious software has developed a tool for recovering the files.

However, the malware does not appear to be ransomware and was only designed to use encryption as bait, while it is a data wiper that deletes almost all files on your drives.

This fake ransomware is an excellent example of how carelessness can lead to data loss.

See also: Cheerscrypt ransomware linked to Emperor Dragonfly hacking group

A possible way to recover from this malware would be to restore your operating system to a previous state, as the fake ransomware does not delete shadow copies.

In general, regularly backing up your most important data would be the best practice, as reinstalling the operating system is the quickest way to deal with a data wiper problem

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS