Criminals encrypt files in extortion attempt

By

Security companies have tracked a new type of internet attack that encrypts files on a user's machine and then demands payment for a decoder tool.

According to Websense, the attack starts when a user visits a malicious website that exploits a known vulnerability in Microsoft Internet Explorer. The site downloads a Trojan that searches for files with various extensions on the user's system and encrypts them.


The Trojan also sends a message to the user's system with instructions on how to buy a tool to decode the files. The message directs users to deposit money for the tool into an online account.

Symantec rated the attack as a Level One threat - the least serious - but said it illustrates the trend of malware writers teaming with criminals intent on profit.

"The attack is yet another indicator of the growing trend of criminals using technology for financial gain," Oliver Friedrichs, senior manager at Symantec Security Response, said in a statement. "The good news is that this threat is not self-propagating, which limits its ability to spread in the wild."

www.symantec.com
www.websense.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

ACSC alerts to exploited MS SharePoint remote code execution flaw

ACSC alerts to exploited MS SharePoint remote code execution flaw

Microsoft knew of SharePoint security flaw in May, initial patch ineffective

Microsoft knew of SharePoint security flaw in May, initial patch ineffective

Qantas obtains court order to prevent third-party access to stolen data

Qantas obtains court order to prevent third-party access to stolen data

Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage

Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage

Log In

  |  Forgot your password?