PDA

View Full Version : Ransom-ware Hits the Internet


Greg
05-24-2005, 10:09 PM
WASHINGTON - The latest threat to computer users doesn't destroy data or steal passwords — it locks up a person's electronic documents, effectively holding them hostage, and demands $200 over the Internet to get them back.

Security researchers at San Diego-based Websense Inc. uncovered the unusual extortion plot when a corporate customer they would not identify fell victim to the infection, which encrypted files that included documents, photographs and spreadsheets.

A ransom note left behind included an e-mail address, and the attacker using the address later demanded $200 for the digital keys to unlock the files.

"This is equivalent to someone coming into your home, putting your valuables in a safe and not telling you the combination," said Oliver Friedrichs, a security manager for Symantec Corp. The company said Tuesday the problem was serious but not deemed a high-level threat because there were no indications it was widespread.

The FBI said the scheme was unlike other Internet extortion crimes. Leading security and antivirus firms this week were updating protective software for companies and consumers to guard against this type of attack, which experts dubbed "ransom-ware."

"This seems fully malicious," said Joe Stewart, a researcher at Chicago-based Lurhq Corp. who studied the attack software. Stewart managed to unlock the infected computer files without paying the extortion, but he worries that improved versions might be more difficult to overcome. Internet attacks commonly become more effective as they evolve over time and hackers learn to avoid the mistakes of earlier infections.

"You would have to pay the guy, or law enforcement would have to get his key to unencrypt the files," Stewart said.

The latest danger adds to the risks facing beleaguered Internet users, who must increasingly deal with categories of threats that include spyware, viruses, worms, phishing e-mail fraud and denial of service attacks.

In the recent case, computer users could be infected by viewing a vandalized Web site with vulnerable Internet browser software. The infection locked up at least 15 types of data files and left behind a note with instructions to send e-mail to a particular address to purchase unlocking keys. In an e-mail reply, the hacker demanded $200 be wired to an Internet banking account. "I send programm to your email," the hacker wrote.

There was no reply to e-mails sent to that address Monday by The Associated Press.

Ed Stroz, a former FBI agent who now investigates computer crimes for corporations, said the relatively cheap ransom demand — only $200 — probably was deliberately low to encourage victims to pay rather than call police and to discourage law enforcement from assigning these cases a high priority.

"That's a very powerful threat," Stroz said. "If somebody encrypted your files, you need this stuff now to do your work."

FBI spokesman Paul Bresson said more familiar Internet extortion schemes involve hackers demanding tens of thousands of dollars and threatening to attack commercial Web sites, interfering with sales or stealing customer data.

Experts said the Web site where the infection originally spread had already been shut down. They also said the hacker's demand for payment might be his weakness, since bank transactions can be traced easily.

"The problem is getting away with it — you've got to send the money somewhere," Stewart said. "If it involves some sort of monetary transaction, it's far easier to trace than an e-mail account."

Details of attack: http://www.websensesecuritylabs.com/alerts/alert.php?AlertID194

Websense Inc.: http://www.websense.com

Lurhq Corp.: http://www.lurhq.com

Symantec Corp.: http://www.symantec.com

ROAR
05-28-2005, 07:38 AM
I read about this....The wonder of technology...bah

Greg
05-28-2005, 01:08 PM
Crazy stuff. No doubt.

vantim
05-29-2005, 12:17 AM
See why you should have Good Updated Anti-Virus, Spyware Scanners, and Firewalls!They should have used a better encryption algorythym. Had they uses AES encryption they wouldn't have been able to decrypt them. I was just reading 1 week ago that as of April 1 2005, AES encryption has never been broken. I'll bet they broke in with sometype of trojan horse and planted a remote control program so they could encrypt the files inside the My Documents folder. This sounds like the work of kids to me.

ROAR
05-29-2005, 09:34 AM
Its may be childs play. But garbage like this, gives some of my more technologically challanged customers fits. In turn, that leads to headaches for me...

vantim
05-31-2005, 12:33 PM
I hear ya there. It's just another reason to get a phone call.

evss
06-07-2005, 12:50 AM
interesting that crime has taken to this step and method today.

vantim
06-15-2005, 07:04 AM
Less physical risk. I would assume the thought of mail order burglary seems tempting.

Dude76
07-22-2005, 12:43 PM
I find this hilarious! haha ransom-ware. On a more serious note, yes it sucks that we now have to deal with yet another internet problem.

bigH2O
07-22-2005, 02:38 PM
Close unneeded ports, keep AV software up to date daily and keep the spyware detection up to date daily.

The only people getting hit by this are the ones that don't practice "safe sex" on the internet. A good tool for ensuring that you are invisible is at https://www.grc.com/x/ne.dll?bh0bkyd2. Follow the instructions, and protect the open ports the utility finds. If you end up with "stealth" on everything, you can forget about somebody sneaking into your system, because your computer doesn't exist to the outside world. Now all you have to do is make sure your virus scanner checks your email before it lands in your in box, and your pop up blocker doesn't allow malicious cookies. Then your set. Computer security is not that difficult.

vantim
08-02-2005, 09:01 AM
Quit surfing porn