Email campaign messages carrying the TorrentLocker ransomware use the DMARC (Domain-based Message Authentication, Reporting and Conformance) technical specification to trick spam filters and return reports to the malicious sender.

DMARC relies on SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail), which are two email validation mechanisms used to determine that the message originates from a host authorized by its domain administrator and that the communication has not been tampered with in between.
The use of DMARC policies is not subject to any restrictions and is available in the public DNS (domain name system), which means that they can be used by both legitimate and malicious parties.
TorrentLocker is a relatively new ransomware with file-encrypting capabilities. It has been detected since August 2014 and has affected thousands of users worldwide. Security researchers found that in one month, cybercriminals were able to collect profits of approximately $224,000 / €200,000.
Data from Trend Micro gathered through its Smart Protection Network platform shows that users in Australia are the main target of this campaign, with an infection rate of 67.7%, starting in November 2014.
Other countries affected by the malware include the US (7.13%), Italy (6.65%), the Philippines (3.09%), and France (2.14%).
Researchers say the campaign has had its ups and downs, with a significant increase recorded in December 2014, followed by a drop in January 2015 and an increase again in February.
By using the DMARC specification, fraudsters can obtain important information about the success of the business, which will allow them to improve their strategy and tactics so that messages reach a greater number of potential victims.
One detail that is available is the amount of messages that failed SPF/DKIM verification and were quarantined or dropped, as well as the number of emails that passed.
Additionally, they will be able to see some data extracted from failed messages (header information and the URIs in the body). This, of course, will only be available if the mail server includes support for this service.
After analyzing SPF and DMARC, researchers observed that the attacker collected data from the rejected emails, which included the name of the Internet Service Provider (ISP), the email provider, contact information, IP addresses, and the SPF and DKIM authentication results.
This is valuable data that allows changing the method of future spam, which can make them more targeted in order to reach a wider audience.
