The makers of the new ransomware are attempting to terrorize users by threatening to make their files public online, in order to get them to pay the ransom demanded.
Ransomware intimidation goes one step further since the developers behind Chimera, in addition to encrypting private files and demanding payment of a sum of money for the decryption key, are now threatening to publish these files on the Internet if the required amount is not paid!
This worrying development was recently observed in a new program called Chimera and detected by Anti-Botnet, a service of the German Internet Industry Association.
The attackers behind the new threat are primarily targeting companies by sending malicious emails to specific employees that pretend to be job applications or job offers. The emails contain a link that leads to a malicious file on Dropbox.
Once Chimera infects a system, it starts encrypting local files. After the first reboot, it displays a ransom note on the user's screen. The attacker demands a payment of around 630 euros in Bitcoin in order to provide the decryption key. So far, there are no differences from regular ransomwares. However, the creators of Chimera have taken this type of intimidation to a new level. There is of course no evidence that any of the victims' data has actually been posted publicly on the Internet, and it is also not yet clear whether this new type of malware actually absorbs user data after encrypting it, but the threat alone could be enough to scare even users who have kept their files in backup.
A typical ransomware simply encrypts files locally and does not transfer them to the C&C server as this requires huge storage space, even if the attackers isolate the theft to only certain file types such as photos.
However, the prospect of something like this happening in the future is very scary, as it could put companies and users at enormous risk.
