Topics:
Security
Buy This Shampoo Or You'll Never See Your Data Again
"In Russia, we're seeing ransom scams, where you infect a company's systems with malware that encrypts data, and you don't provide the decryption key until money is paid," Uriel Maimon, a researcher with RSA's consumer solutions division, told me a few weeks ago when I was researching the story. In one variant of a ransom attack that RSA encountered, a Trojan (targeting mostly individuals in Russian-speaking countries) encrypts all the files in the user's "My Documents" folder using a symmetric block cipher using an algorithm, a process that's the Russian counterpart to the Data Encryption Standard, or DES, algorithm, Maimon said. These encrypted files are kept as a single file and the victim is instructed to make a purchase of at least $75 at an online pharmacy in order to get back their data. How's that? Maimon even provided the verbatim text of the ransom note: "INSTRUCTIONS HOW TO GET YOUR FILES BACK READ CAREFULLY. IF YOU DO NOT UNDERSTAND - READ AGAIN. This is followed by step-by-step instructions that include a link to enter www.healthservices.info. Once there, the victim is told to buy any product from the site. Once this is done, the victim must send an e-mail with their order ID to the ransomer's e-mail address. A password is then sent to the victim's e-mail address as soon as the person running the ransom verifies the order ID, usually within four hours. The victim then gets back their information in an encrypted file. All the e-mails with invalid order IDs are ignored. OK, here's where it get really weird -- the ransom note writer even guarantees the victim that they'll receive the product they ordered, which they're told they can use or resell to "earn extra money because all the products in our online pharmacy are discounted!" The ransomer also guarantees that the victim will never be asked to buy anything in their online pharmacy again. The note closes with the caution, "Remember you are just three steps away from your files." « Bring Your Own Hotspot! | Main | VoIP: Coming To A Smartphone Near You » |
| Sign Up Now For InformationWeek News Alerts |