Ransomware Extortion Scam Locks Machines, Demands Payment
 
Contributed by: Email on 12/21/2012 04:17 PM 
[
 Comments
]
 Comments
]
 
The latest ransomware scam is locking down infected machines and displaying localized webpages warning users that their computer contains banned material and wont be unlocked until a fine is paid, according to a report from McAfees Naganathan Jawahar. 
The Trojan displays a warning, purportedly from the FBI, Metropolitan Police (London), or other law enforcement agencies, that consumes a users entire screen. The warning informs users that some illegal content has been found on their computer and the user wont be given access to their machine unless they pay the fine.
Its not altogether clear where the infections are coming from. The scammers are offering to unlock affected computers after receiving a £100 payment via Green Dot MoneyPak, Paysafecard, or Ukash financial transfer services. Jawahar writes that paying the fine wont necessarily fix infected machines.
The Trojan is also reportedly downloading custom DLL payloads, like Lock.dll, which it uses to inject the fraudulent messages into the processes of Internet Explorer, Chrome, and Opera browsers.
McAfee is calling the malware payload, Ransom-AAY.gen.b.You can read McAfees report here.
  
The Trojan displays a warning, purportedly from the FBI, Metropolitan Police (London), or other law enforcement agencies, that consumes a users entire screen. The warning informs users that some illegal content has been found on their computer and the user wont be given access to their machine unless they pay the fine.
Its not altogether clear where the infections are coming from. The scammers are offering to unlock affected computers after receiving a £100 payment via Green Dot MoneyPak, Paysafecard, or Ukash financial transfer services. Jawahar writes that paying the fine wont necessarily fix infected machines.
The Trojan is also reportedly downloading custom DLL payloads, like Lock.dll, which it uses to inject the fraudulent messages into the processes of Internet Explorer, Chrome, and Opera browsers.
McAfee is calling the malware payload, Ransom-AAY.gen.b.You can read McAfees report here.
Comments







