HomeSecurityFake incoming "Fax Report" emails contain ransomware

Fake incoming “Fax Report” emails contain ransomware

Once again, fake incoming “Fax Report” emails containing malware are being sent to random users.

Given the popularity of online faxing services, it's likely there will be many victims.
The email often follows the same repetitive format:

 

Fax Report

Most of the time, the subject of the fake Fax Report is something related to payroll, or internal reports, and the malicious file is hosted on an online file storage account that is connected via the email message.

In this case, the email carries the malware in the attached document.

According to Dr.Web researchers, the file – an SRC file – is a Trojan downloader that, once run, decompresses and runs encrypted ransomware.

"The ransomware then encrypts the data stored on the disk and demands a ransom to recover it. Files affected by the ransomware are not subject to a change in their filename extension, but instead have '!crypted!' at the beginning of their name. During the encryption process, the malware creates temporary files with the *.cry which are later deleted," the researchers explain, stressing that, unfortunately, it is currently impossible to decrypt files affected by the ransomware.

Users are advised to regularly back up their important files, and to think twice before opening attachments or clicking on links from unsolicited emails or such Fax Report.

Noting that campaigns for this type of malware in Fax Report messages take place at regular intervals, this will certainly not be the last time users are warned about this malware. Unfortunately, this distraction of users lasts only a short time for the campaign to work successfully.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS