The Register® — Biting the hand that feeds IT

Feeds

Devious decryption scam rides ransomware Trojan

We can remember it for you wholesale

Agentless Backup is Not a Myth

Devious virus writers have come up with a new twist on ransomware-style malware.

A new strain of Trojan encrypts recently-opened files on compromised Windows PCs. But instead of demanding a ransom for a decryption key to unlock files, the malware relies on users to search the web for a possible way-out.

Hackers have cleverly baited searches for likely terms, with links to sites offering a supposed fix actually developed by the crooks behind the ruse.

A fuller explanation of the scam can be found Symantec's write-up on the Ramvicrype Trojan here and in a blog posting by Symantec researcher Shunichi Imano here. ®

Steps to Take Before Choosing a Business Continuity Partner

Latest Comments

Not the first time

We've seen this tactic before. Back in 2006 we saw a Trojan that encrypted the contents of My Documents and then dropped a file that had "instructions" on how to get your stuff back. It usually involved sending money or buying stuff from a CanPharm page. Here's the post if you are interested: http://www.sophos.com/pressoffice/news/articles/2006/06/arhiveus.html

and here's the money tactic: http://www.sophos.com/pressoffice/news/articles/2006/03/zippo.html

What these scammers won't do for money.

0
0
Anonymous Coward

It's normally a good idea...

...to be familiar with at least one legitimate resource when it comes to things like these, I have my go-to guys online, they're tried and tested and have saved my backside more than once over the years, I'd go directly to their URL in a case like this.

0
0

Could this Fail?

I'm sure that security firms will be able to get their pages to trump the scammers' on search engine ranks for those key words.

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?