HomeSecurityAnd PC "kidnappings" by hackers

And PC "kidnappings" by hackers

15s20pc-thumb-large
More and more hackers are developing malicious software that blocks the machines they "infect", demanding a fee from the user to unlock it.

Hostages, kidnappings, ransom. Words that, in addition to international reports on the actions of pirates in Somalia, are increasingly appearing in technology articles, which describe the mass "kidnappings" of computers by cybercriminals, who hold the stored data "hostage" and blackmail their owners for a "ransom" in order to release it. The reason is that recently more and more hackers have been developing malicious software that blocks the machines they "infect", demanding a fee from the user to release them.

This type of malware is called ransomware and has become one of the most significant cyber threats for both individual users and businesses. According to Symantec's latest Internet Security Threat Report, ransomware variants increased by 500% in 2013 compared to 2012, infecting 861,000 machines worldwide in just one month (November 2013).

Naturally, such malware occasionally appears in our country: the most recent case is CTB-Locker, for which the Cybercrime Directorate issued a statement at the end of July, warning Greek users. Besides, if the history of ransomware begins in 2009, it took just three years for the first widespread “representative” of the species to appear in Greece. Known by the nickname “police virus”, this virus blocked the computer, supposedly by the police authorities who had detected child pornography and emails with terrorist content on the machine, demanding the payment of a “fine” of 100 euros to unlock it.

Nowadays, however, the majority of cybercriminals do not “submit” to the police and, instead of a warning from law enforcement, a message appears on the screen that states without any distortion the purpose of the “infection”. One reason is that today’s ransomware is much more sophisticated than the “police virus”, which could have been removed relatively easily. The main one, however, is that many of these malicious programs encrypt the stored data, making it usually impossible to recover without the “assistance” of hackers.

In these cases, hackers encrypt data using two “keys,” a public one that they give to the user and a private one that they hide on a server and for which they essentially demand a “ransom.” At the same time, they often ask for the amount to be paid in bitcoin, so that the transaction leaves as few traces as possible that could lead to their detection.

Beyond the technical advantages of this method, perhaps an even greater advantage is the logic behind ransomware, namely the extraction of relatively little money from many victims, as the money required to "liberate" each computer ranges from $60 to $200 - an amount that a user may be tempted to pay.

Easy profit

This logic seems to be working: according to the FBI, Cryptolocker, one of the most famous malware of its kind, had earned its creators $27 million in two months. So it is not surprising that, after the international police operation in June that led to its inactivation, new and more sophisticated variants have already appeared, such as CTB-Locker and CryptoWall. As for Cryptolocker, however, a site (Decrypt Cryptolocker) has been created to unlock infected PCs without paying money.

At present, most cases concern Windows computers, because their operating system is very widespread and therefore a larger “pool” of potential victims. On the other side of the Atlantic, however, last summer a ransomware for Mac appeared. At the same time, with the spread of “smart” devices, cybercriminals are starting to turn to smartphones and tablets. In fact, cybersecurity company ESET detected the first ransomware for Android a few weeks ago, which is disguised as an application for playing videos and can encrypt files located on the microSD card. Last May, “hijackings” of iPhones and iPads were also reported, mainly in Australia.

What do the experts advise?

All cybersecurity companies, as well as law enforcement agencies, advise users not to pay the "ransom" if their devices fall victim to digital... "hostage". And this, for the simple reason that nothing guarantees that cybercriminals will actually unlock their computer. On the contrary, they advise that one keep backup copies of their files on an external storage medium or an online service, which they will update at regular intervals, in order to limit the damage in the event that the machine is "hijacked". And, in such a case, to contact a specialist, who will probably be able to at least "unlock" the device.

Also, like other types of malware, ransomware is often spread through emails that contain "infected" files or links that lead to sites that, by exploiting "vulnerabilities" in the operating system or browser, manage to install the malware. Therefore, users should not only not open emails from unknown senders, but also ensure that the vulnerabilities on their device are as few as possible.

That is why it is necessary to update the operating system and browser with the latest available updates, which usually address such vulnerabilities. As well as using a security suite, which is very likely to detect the potential "intruder" and prevent its installation. Finally, one should be careful about the programs that one "downloads" to one's device, making sure that they come from a source that one trusts.

 

Source: kathimerini.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS