Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Geek it 'till it MHz.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. Smart Defrag
2. GS Auto Clicker
3. Macrium Reflect FREE Edition
4. Sergei Strelec's WinPE
5. MusicBee
6. Visual C++ Redistributable Runtimes AIO Repack
7. K-Lite Mega Codec Pack
8. ImgBurn
9. Unlocker
10. Format Factory
More >>

top reads

Star 8 Windows Shortcuts That’ll Make You More Productive and Save You Time

Star Windows 10 Not Dead Yet - You Can Still Get Updates For Free

Star What is a '400 Bad Request - Request Header or Cookie Too Large' Error and How to Fix It

Star How to Fix Windows Install Error 0xC1900101

Star How to Force Enable Windows 10 Extended Security Updates If The Option Is Not Showing

Star Windows 11 25H2 is Out: What’s New and How to Get It Now.

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star Boost Your PC Speed with ReadyBoost: How a Thumb Drive Can Enhance Your System's Performance

Star 5 Hidden Windows Tools You’ve Had All Along But Never Use

Star Use the Windows 10 Media Creation Tool Before Support Ends For Windows 10 in 2025


MajorGeeks.Com » News » December 2012 » FBI Warns of New Twist to Reveton, Citadel Malware Scams

FBI Warns of New Twist to Reveton, Citadel Malware Scams


Contributed by: Email on 12/01/2012 02:56 PM [ comments Comments ]


The cybercrime group behind the Citadel malware and Reveton ransomware has upped the stakes with a new extortion technique, the FBI's Internet Crime Complaint Center said today.

Reveton scams have now co-opted the Internet Crime Complaint Center with a new fake warning to users whose computers have been infected.

"In addition to instilling a fear of prosecution, this version of the malware also claims that the user’s computer activity is being recorded using audio, video, and other devices," an FBI advisory said.

Victims usually are lured to a website hosting the malware. Once Reveton has been installed, the victim's computer is locked up and a screen materializes with a warning that Federal law has been violated. The victim also sees a message that the FBI has determined that the user's IP address has accessed child pornography and other illicit content.

The victim is instructed that the only way to unlock their computer is to pay a fine via a prepaid money card service, the FBI said.

"In addition to the ransomware, the Citadel malware continues to operate on the compromised computer and can be used to commit online banking and credit card fraud," the advisory said.

Despite the fact that some victims have paid up, they quickly learn they've been scammed and their machines are not unlocked.

The FBI has warned about Reventon infections before but earlier scams did not threaten victims with video and audio surveillance.

Citadel is a constantly evolving malware platform. In October, its authors update the malware with a dynamic configuration module that allows them to inject code directly into compromised browsers in real time.

This new feature lessens the chance that the malware would be detected by security software since this would eliminate the need for update configuration files to be sent to each bot.

"This shows us that this team is really serious. Their development skills are very strong; these are not amateurs,” siad Limor Kessem of RSA Security in an interview with Threatpost.

The Dynamic Config injection mechanism keeps a botmaster from having to open external communications channels to send injection files or updates to configuration files. Once a victim is compromised, Kessem said, the botmaster can use HTML or java script  injections on legitimate banking or ecommerce pages and via a java script  popup, for example, ask a user for additional log-in or personal information such as date of birth or a Social Security number.

Citadel is an advanced platform. It updates almost quarterly with new features that indicate a level of professional development, organization and resources. It also runs on an open source model of sorts, support its own customer relationship management, support teams and user forums where issues are discussed.

In July, experts noted chatter that Citadel might be taken off the market in underground forums and updates would be limited only to existing customers.






« Worm Tries AutoRun, Then Social Engineering to Infect · FBI Warns of New Twist to Reveton, Citadel Malware Scams · Dolphin bites girl at SeaWorld Orlando »




Comments
comments powered by Disqus

MajorGeeks.Com » News » December 2012 » FBI Warns of New Twist to Reveton, Citadel Malware Scams

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition