HomeSecurityTeslaCrypt - Scams disguised as Customer Service

TeslaCrypt – Scams disguised as Customer Service

The scammers behind the TeslaCrypt ransomware have managed to collect $76,500 in about 10 weeks, according to new research.

TeslaCrypt ransomware was first discovered in February 2015 by security researchers at Dell SecureWorks.

TeslaCrypt - Scams disguised as Customer Service

After encrypting files on its victims' systems, TeslaCrypt demands a ransom of $150 or more, paid in Bitcoin. The malware uses the anonymous Tor network to hide the crooks and command-and-control servers.

Cisco security researchers were able to analyze and crack the TeslaCrypt ransomware. So in late April, they released a decryption utility. But the release of the data recovery tool turned the entire foundation of the scam upside down.

The latest study by security researchers at FireEye followed the money trail that ransomware makes.
TeslaCrypt - Scams disguised as Customer ServiceWe tracked victims’ payments to the crooks, which were available because the group used Bitcoin. We found that between February and April 2015, the perpetrators extorted $76,522 from 163 victims. That may seem insignificant compared to the millions earned annually by other cybercrimes , or the estimated $3 million earned by CryptoLocker crooks over a nine-month period in 2013-14.

However, even this modest performance demonstrates ransomware's ability to generate profits and its devastating impact on its victims.

“Some fear they will be expelled from school or fired from their employers if they don’t recover their files,” says Nart Villeneuve, principal threat analyst at FireEye.

“Fathers and mothers feel devastated when they lose family photos. The TeslaCrypt ransomware has even hit non-profit organizations, such as organizations dedicated to treating blood cancer, as well as many other small businesses. Many of the malware’s victims were unable to afford to pay the ransom.”

Ransomware scams have been going on for years, and while CryptoLocker was a pioneer in this area, TeslaCrypt innovated much more by creating a full-fledged “Technical Support” network.

“Criminals pose as ‘customer support’ to help their victims find the Bitcoins to pay the ransom,” Villeneuve explains.

Of the 1,231 known victims, 163 paid the ransom. Victims communicate with the criminals via a messaging system.

“We expect ransomware to continue to be developed by criminals in the coming years,” Villeneuve concludes.

"The tools are easy to use, and even inexperienced attackers can make quick profits from victims desperately trying to recover their files and pay the ransom."

 

Source: iguru

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS