| Author | Post |
|---|---|
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | For PC Virus Victims, Pay or Else By NICOLE PERLROTH Published: December 5, 2012 CULVER CITY, Calif. — Kidnappers used to make ransom notes with letters cut out of magazines. Now, notes simply pop up on your computer screen, except the hostage is your PC. In the past year, hundreds of thousands of people across the world have switched on their computers to find distressing messages alerting them that they no longer have access to their PCs or any of the files on them. The messages claim to be from the Federal Bureau of Investigation, some 20 other law enforcement agencies across the globe or, most recently, Anonymous, a shadowy group of hackers. The computer users are told that the only way to get their machines back is to pay a steep fine. And, curiously, it’s working. The scheme is making more than $5 million a year, according to computer security experts who are tracking them. The scourge dates to 2009 in Eastern Europe. Three years later, with business booming, the perpetrators have moved west. Security experts say that there are now more than 16 gangs of sophisticated criminals extorting millions from victims across Europe. The threat, known as ransomware, recently hit the United States. Some gangs have abandoned previously lucrative schemes, like fake antivirus scams and banking trojans, to focus on ransomware full time. Essentially online extortion, ransomware involves infecting a user’s computer with a virus that locks it. The attackers demand money before the computer will be unlocked, but once the money is paid, they rarely unlock it. In the vast majority of cases, victims do not regain access to their computer unless they hire a computer technician to remove the virus manually. And even then, they risk losing all files and data because the best way to remove the virus is to wipe the computer clean. It may be hard to fathom why anyone would agree to fork over hundreds of dollars to a demanding stranger, but security researchers estimate that 2.9 percent of compromised computer owners take the bait and pay. That, they say, is an extremely conservative estimate. In some countries, the payout rate has been as high as 15 percent. That people do fall for it is a testament to criminals’ increasingly targeted and inventive methods. Early variations of ransomware locked computers, displayed images of pornography and, in Russian, demanded a fee — often more than $400 — to have it removed. Current variants are more targeted and toy with victims’ consciences. Researchers say criminals now use victims’ Internet addresses to customize ransom notes in their native tongue. Instead of pornographic images, criminals flash messages from local law enforcement agencies accusing them of visiting illegal pornography, gambling or piracy sites and demand they pay a fine to unlock their computer. Victims in the United States see messages in English purporting to be from the F.B.I. or Justice Department. In the Netherlands, people get a similar message, in Dutch, from the local police. (Some Irish variations even demand money in Gaelic.) The latest variants speak to victims through recorded audio messages that tell users that if they do not pay within 48 hours, they will face criminal charges. Some even show footage from a computer’s webcam to give the illusion that law enforcement is watching. The messages often demand that victims buy a preloaded debit card that can be purchased at a local drugstore — and enter the PIN. That way it’s impossible for victims to cancel the transaction once it becomes clear that criminals have no intention of unlocking their PC. The hunt is on to find these gangs. Researchers at Symantec said they had identified 16 ransomware gangs. They tracked one gang that tried to infect more than 500,000 PCs over an 18-day period. But even if researchers can track their Internet addresses, catching and convicting those responsible can be difficult. It requires cooperation among global law enforcement, and such criminals are skilled at destroying evidence. Charlie Hurel, an independent security researcher based in France, was able to hack into one group’s computers to discover just how gullible their victims could be. On one day last month, the criminals’ accounting showed that they were able to infect 18,941 computers, 93 percent of all attempts. Of those who received a ransom message that day, 15 percent paid. In most cases, Mr. Hurel said, hackers demanded 100 euros, making their haul for one day’s work more than $400,000. That is significantly more than hackers were making from fake antivirus schemes a few years ago, when so-called “scareware” was at its peak and criminals could make as much as $158,000 in one week. Scareware dropped significantly last year after a global clampdown by law enforcement and private security researchers. Internecine war between scareware gangs put the final nail in the coffin. As Russian criminal networks started fighting for a smaller share of profits, they tried to take each other out with denial of service attacks. Now, security researchers are finding that some of the same criminals who closed down scareware operations as recently as a year ago are back deploying ransomware. “Things went quiet,” said Eric Chien, a researcher at Symantec who has been tracking ransomware scams. “Now we are seeing a sudden ramp-up of ransomware using similar methods.” Victims become infected in many ways. In most cases, people visit compromised Web sites that download the program to their machines without so much as a click. Criminals have a penchant for infecting pornography sites because it makes their law enforcement threats more credible and because embarrassing people who were looking at pornography makes them more likely to pay. Symantec’s researchers say there is also evidence that they are paying advertisers on sex-based sites to feature malicious links that download ransomware onto victims’ machines. “As opposed to fooling you, criminals are now bullying users into paying them by pretending the cops are banging down their doors,” said Kevin Haley, Symantec’s director of security response. More recently, researchers at Sophos, a British computer security company, noted that thousands of people were getting ransomware through sites hosted by GoDaddy, the popular Web services company that manages some 50 million domain names and hosts about five million Web sites on its servers. Sophos said hackers were breaking into GoDaddy users’ accounts with stolen passwords and setting up what is known as a subdomain. So instead of, say, www.nameofsite.com, hackers would set up the Web address nameofsite.blog.com, then send e-mails to customers with the link to the subdomain which — because it appeared to come from a trusted source — was more likely to lure clicks. Scott Gerlach, GoDaddy’s director of information security operations, said it appeared the accounts had been compromised because account owners independently clicked on a malicious link or were compromised by a computer virus that stole password credentials. He advised users to enable GoDaddy’s two-step authentication option, which sends a second password to users’ cellphones every time they try to log in, preventing criminals from cracking their account with one stolen password and alerting users when they try. One of the scarier things about ransomware is that criminals can use victims’ machines however they like. While the computer is locked, the criminals can steal passwords and even get into the victims’ online bank accounts. Security experts warn to never pay the ransom. A number of vendors offer solutions for unlocking machines without paying the ransom, including Symantec, Sophos and F-Secure. The best solution is to visit a local repair shop to wipe the machine clean and reinstall backup files and software. “This is the new Nigerian e-mail scam,” Mr. Haley said. “We’ll be talking about this for the next two years.” [Link] |
| killbillvol69 All-Star Member ^Lucy Pinder 18631 Posts 4/08 | |
| ninja1 Senior Member 2939 Posts 1/08 | |
| killbillvol69 All-Star Member ^Lucy Pinder 18631 Posts 4/08 | |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | Power the computer off by the power switch -- before you click on anything -- is one of the best courses of action when these things present themselves. Safe-mode (repeatedly tapping F8 before Windows boots to get there) is your friend :) Malwarebytes -- in addition to your active malware/virus solution -- is a necessary tool to keep on hand. Even SpyBot is useful. When I was hit with one of the rogue anti-virus scams a couple of years ago, both Malwarebytes and SpyBot were able to clean things the other didn't/couldn't, in addition to my active malware/virus solution (which also didn't/couldn't find and clean everything, either). Then, I had to intelligently remove some things by hand -- even after all three utilities did their work! CCleaner is also a mandatory utility to have on your computer. One thing it will make extremely easy, is to remove items from the Startup folder that many malicious executables leave there (which will just help the bad guys re-install the malware, after you already spent time painstakingly removing it, when you boot your computer back up in mormal-mode). Utilities and cleaners often miss these little gotchas. |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | http://live.vipreantivirus.com/ DO NOT TYPE "www." You can actually just type "live.vipreantivirus.com" into your browser to get there. I strongly recommend downloading and preserving a copy of VIPRE Rescue NOW, and keeping it on a flash-drive, CD/DVD and/or external hard-drive, so that you have it available when you need it. Keep a current copy on your computer also, as you often navigate to it once you've successfully booted into Safe-mode (FYI, "Safe-mode with networking" is your best option). (Also, if you're the go-to computer person in your circle of friends, this is a life-saver when dealing with other people's computers -- the ones with no malware/virus protection and nothing updated and kept current.) ------------------------------------ 2012-12-09 viprerescue14388 .exe Current version can be downloaded at: http://live.vipreantivirus.com/ live.vipreantivirus.com ------------------------------------ VIPRE Rescue Version: viprerescue14388 .exe The VIPRE Rescue is designed to disinfect a system that is so infected that a user cannot install VIPRE. * VIPRE Rescue is a free utility. It does not replace VIPRE. It is meant for the type of infections and situations we're discussing here. VIPRE Rescue is a handy, easy to use tool designed to clean your computer if you are already infected with a virus and your operating system is not working properly as a result of the infection. If you are already running VIPRE and a virus has disabled it, you can still run this program to clean your computer. ------------------------------------ Instructions: 1. Boot the computer in "Safe Mode " (press F8 when the computer starts to boot). When the boot screen appears, use the down arrow to highlight the selection. 2. Download the VIPRE Rescue application. You can use a different computer to do this if needed. 3. Save it to a USB drive or other portable media. 4. Run the file called viprerescue14388 .exe <<< or the latest current version 5. Click Yes to extract VIPRE Rescue. 6. Click Unzip. 7. Sit back and allow VIPRE to clean your machine. ------------------------------------ VIPRE Rescue antivirus definitions change daily. Check the website to get the latest definitions. http://live.vipreantivirus.com/ live.vipreantivirus.com |
| Janitor Retired Porno movies, sexy videos, xxx. Adult DVD Talk at your service. 6409 Posts 11/99 | |
| charn fubar 2880 Posts 12/09 | |
| killbillvol69 All-Star Member ^Lucy Pinder 18631 Posts 4/08 | I tried the vipre thing, and it keeps making my computer turn off before it's finished. Once it went 10 minutes, once about 40 mins, and once about 20 mins before it conked out on me. Gonna try malwarebytes now. |
| killbillvol69 All-Star Member ^Lucy Pinder 18631 Posts 4/08 | |
| BigBoy Senior Member 3359 Posts 1/03 | I don't know. BUT ... When my PC was struck I had to disconnect or power-down my modem because no matter what I did it would lock up. Even if I did NOT open a browser window the virus would -- taking my browser to a phony FBI screen that said I had to get a money gram so that they could clean my PC. Try virus protection when your computer can't access the web. |
| killbillvol69 All-Star Member ^Lucy Pinder 18631 Posts 4/08 | Thanks so much to Goldstein for starting this thread, and thanks to everyone who posted in it about their experiences. Had I not seen this thread, I would have freaked the fuck out. I don't know if I would have actually paid, but I definitely would have paid someone else to fix my computer for me. If I ever meet Goldstein, or ninja1, or BigBoy in real life... the first one's on me guys. |
| killbillvol69 All-Star Member ^Lucy Pinder 18631 Posts 4/08 | It was the first time I had visited that pay site, and after clicking on the "tour" button, like 10 seconds later I got the virus. Not sure if it's good to post the name of the site here or not. |
| BigBoy Senior Member 3359 Posts 1/03 | |
| killbillvol69 All-Star Member ^Lucy Pinder 18631 Posts 4/08 | |
| Janitor Retired Porno movies, sexy videos, xxx. Adult DVD Talk at your service. 6409 Posts 11/99 | |
| killbillvol69 All-Star Member ^Lucy Pinder 18631 Posts 4/08 | |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | If you don't already have CCleaner, I highly recommend you get it (download the free version from the Piriform.com link). In addition to using the "Cleaner" function on a regular basis, I strongly recommend you use this now to take a look in your Startup folder for anything that looks suspicious. Launch CCleaner > select "Tools" > select "Startup" You will have three options available for managing what is in the Startup folder: Enable... Disable... and Delete. This is light-years easier than using Windows to modify the folder! Also, you can disable suspicious items first (as opposed to outright deleting them), to be sure you're not fooling with something you actually "need." ![]() ALSO, I highly recommend making sure now that your Java, Flash and Adobe Reader are all updated and current. AND, take a look at the Adobe Flash Player Website Storage Settings Panel, and see what Flash cookies are being stored on your computer. Flash cookies are very invasive, are not normally deleted when you clear your browser cookies, and are often used to restore your regular browser cookies when you're not looking. I recommend deleting whatever Flash cookies you find stored on your computer (unless you recognize a cookie for a paid site you are subscribing to... leave those if you wish). The "Website Storage Settings panel" you see at the link is the actual control panel (it is not just a picture)! FYI, CCleaner will delete Flash cookies, too, if you tell it to do so. Finally, you may want to run VIPRE Rescue from within Safe Mode, now that you presumably can, to see what else it comes up with. I suggest doing this overnight, as it can take a long time (hours) to complete. I'd also run SpyBot while your at it, as I have found that different utilities find things the others don't -- and ALL of them often find additional things, when you run them a 2nd and 3rd time, after clearing out "round one" of the bad stuff. These infections are seldom simple, and seldom 100% resolved with the "round one" cleaning. Traces are usually strewn all over the place that enable the infection to reassert itself again. Remember, check out that Startup folder using CCleaner! |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | These are often called "spring-loaded" windows, that are NOT doing what they pretend to be doing when you click on them. A safe way to close a suspicious pop-up or window, is to close the window using the combination "Alt + F4" (instead of clicking on the box). Sometimes you will start seeing suspicious dialogue box(es) (you know, the ones wanting you to click "OK" to something). I treat these as highly suspicious, especially if they are asking you to confirm something that has nothing to do with what you're actually doing. The confusion many people experience when being bombarded with pop-ups and odd dialogue boxes often leads to their clicking on everything to try and close them -- then, BAM!, you're infected! The malware bastards are counting on this human nature response to trick you into helping them infect you. Be smart, press and hold your power button on the computer and force a hard shut-down. If you are presented with windows that keep popping-up after you've closed them, or refuse to respond to the "Alt + F4" option, I highly suggest exiting the program if you can. If you can't exit the program, press and hold your power button on the computer and force a hard shut-down -- but get the hell out of there! After forcing a hard shut-down: To be on the safe side, I will typically reboot in Safe Mode and run Malwarebytes (in the "perform quick scan" mode), which will only take a couple of minutes to complete. If it comes back clean, go ahead and reboot again normally. If it finds anything, clean it, then go ahead and run Malwarebytes again, but now in the "perform full scan" mode. Generally, I will stay in Safe Mode and run all my utility programs until they all come back clean. Then, see my "CCleaner post" above this one :) Remember, the bad guys today are more often exploiting vulnerabilities in Java, Flash and Adobe Reader, as opposed to a direct attack on Windows itself, to infect you and make your lives miserable. |
| astroknight Questionable Moderator Tastes so good... 4187 Posts 11/99 | |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | I'm just browsing the Internet, and out-of-nowhere I get the dialogue telling me that an installation is about to take place and did I want to create a checkpoint first. Needless to say, I wasn't doing an install! So, rather than respond in any way, I held the power button and forced a hard shut-down. Re-booted in Safe Mode, ran some utilities, did some cleaning up, and everything came back clean. I can't help but think I dodged some kind of attack. |
| cubesnake Senior Member 3858 Posts 10/02 | --------------------------------------------------------------------------------------- Avira AntiVir Rescue System The Avira AntiVir Rescue System allows access to computers that cannot be booted. This makes it possible to repair a damaged system, to rescue data or to scan for virus infections. Just double-click on the rescue system package to burn it to a CD/DVD which can boot an unresponsive system. The Avira AntiVir Rescue System is updated several times a day so that the most recent security updates are always available. --------------------------------------------------------------------------------------- just get the ISO file and burn a CD http://www.avira.com/en/download/product/avira-antivir-rescue-system If the CD boots up and can not find the network adapter just make a setup by hand and get the latest antivirus signatures. Then check a few more boxes and then hit run ... takes a while (on a slow pc i had it running for 4+ hours) It kills what it knows . Then after reboot let it run again and again until it doesn´t find anything anymore helped me on several pcs Cube |
| von_swine Member Dominance & Persecution. 919 Posts 1/04 | the next couple of DL's I tried (& paid for) were worthless; PC Tuneup and another crack at Malwarebytes Pro both failed, but, HitmanPro.NL offered a free DL that wroked great, so I just purchased it after the trial expired and have little or no probs since. now, if you get hit w/Ramsomware and cant even logon to your main user account just go through your guest account/logon and DL the Hitman free trial form there (to a flash drive if you have one!) and you'll be clear in no time. sorry if I've stated the obvious here as I didnt read everyone's posts verbatim, but still wanted to add what I found to work best against Ransomware once it gets into your Java and startup programs,..that's all for now,.. lates, Von S. |
| wcw43921 Senior Member Look Into My Eyes-- 1252 Posts 4/08 | _________________________________________________________________________________
|
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | Hackers Find New Ways to Breach Computer Security News Analysis By IAN URBINA JUNE 21, 2014 THE perpetual cat-and-mouse game between computer hackers and their targets is getting nastier. Cybercriminals are getting better at circumventing firewalls and antivirus programs. More of them are resorting to ransomware, which encrypts computer data and holds it hostage until a fee is paid. Some hackers plant virus-loaded ads on legitimate websites, enabling them to remotely wipe a hard drive clean or cause it to overheat. Meanwhile, companies are being routinely targeted by attacks sponsored by the governments of Iran and China. Even small start-ups are suffering from denial-of-service extortion attacks, in which hackers threaten to disable their websites unless money is paid. Just days after the F.B.I. and international law enforcement agencies teamed up earlier this month to kill one ransomware program, CryptoLocker, which had infected over 300,000 computers, another pernicious program, Cryptowall, popped up and began spreading rapidly. In response, more companies are resorting to countermeasures like planting false information on their own servers to mislead data thieves, patrolling online forums to watch for stolen information and creating “honey pot” servers that gather information about intruders. Last year, companies also spent roughly $1.3 billion on insurance to help cover expenses associated with data theft. Some security experts are urging even more aggressive action. “Companies want better results than are being delivered by law enforcement,” said Stewart A. Baker, former assistant secretary for policy at the Department of Homeland Security. He questioned whether the National Security Agency, the F.B.I. or the C.I.A. had enough qualified counterhackers to stake out corporate networks and also whether those businesses would be comfortable giving the government more access to their networks. Mr. Baker maintains that victims of data theft can reasonably argue that they have a right to follow and retrieve stolen data wherever the thief takes it. And, he added, federal law on the matter is so ambiguous that prosecuting a company for trespassing on the domain of a hacker would be difficult and highly unlikely. “I do really believe there should be a Second Amendment right in cyber,” added Jeffery L. Stutzman, vice president of Red Sky Alliance, referring to the right to bear arms. His company coordinates intelligence sharing for many of the world’s top corporations. Virtually all of them are weighing how aggressive to be in combating hackers, he said. In 2011 Michael Hayden, former director of both the C.I.A. and the N.S.A., suggested that the government should consider allowing a “digital Blackwater” with paid mercenaries battling cyberattackers on behalf of corporations. But security experts warn that by taking matters into their own hands companies risk an escalating cycle of retaliation, lawsuits or Internet traffic jams. What’s more, since cybercriminals typically hijack the systems of unwitting third parties to launch attacks, it is often hard to pinpoint targets for retaliation, said Orin S. Kerr, a professor at the George Washington University Law School. It is “kind of like a blindfolded partygoer trying to hit a piñata with a baseball bat,” he said. “He might hit the piñata but he might hit Aunt Sally, who happens to be standing nearby.” Companies might also trip up law enforcement efforts or find themselves on the wrong end of a lawsuit if they inadvertently gain access to someone else’s server. And under many foreign laws, self-defense actions by private companies amount to espionage. The Justice Department takes the stance that a company is most likely breaking the law whenever it gains access to another computer network without permission. At a panel hosted by the American Bar Association, John Lynch, chief of the computer crime and intellectual property section of the Justice Department’s criminal division, said that usually, when his office determines that companies have gone outside their server to investigate a perceived attacker, his first thought is, “Oh wow — now I have two crimes.” There are, however, other ways to fight hackers that are both legal and effective, said Mr. Stutzman of Red Sky Alliance. His firm, for example, profiles attackers by keeping their pictures, phones numbers and other personal data on file. He is also an advocate of software that tags sensitive documents so that if they are stolen they self-destruct or transmit an alert to the owner. Most security companies say the main objective should be raising the cost to hackers. CloudFlare, for instance, has developed a service called Maze, which it describes as “a virtual labyrinth of gibberish and gobbledygook” designed to divert intruders to bogus data and away from useful information. Other companies create bottlenecks to route attackers through security checkpoints. It is fairly common for law firms to have their email read during negotiations for ventures in China, said Dmitri Alperovitch, a founder of CrowdStrike, a company that investigates hackers. So if a company knows its lawyers will be hacked, planting decoys can give them an upper hand, he said. This month CrowdStrike unmasked a secret cell of cyberthieves linked to the Chinese Army that had stolen millions of dollars’ worth of data from military contractors and research companies, often by hiding its attack software in emailed invitations to golfing events. Samir Kapuria, vice president of Symantec’s Cyber Security Group, recounted how his company helped a major manufacturer create bogus blueprints of a valuable product with a traceable but harmless flaw and left it hidden in its servers. When the manufacturer later found the planted blueprint for sale on the black market, he said, Symantec was able to help trace the leak to its source, fire the subcontractor and save the manufacturer tens of millions of dollars. But there can also be unintended consequences when planting false information, said Dave Dittrich, a security engineer at the University of Washington. He offered a theoretical example in which a company intentionally inserts flaws into a faked vehicle design. “If someone plants false information to be stolen and used, and this results in the death of any innocent human beings,” he said, “there could be a good case made that the entity who planted the fake data is acting in a negligent and unjustifiable manner.” In general, Mr. Kapuria of Symantec prefers a philosophical approach toward thwarting the legions of cybercriminals, describing the fight as “Cyber Sun Tzu — when the enemy is relaxed, make them toil; when full, make them starve; when settled, make them move.” |
| pringles All-Star Member 1351 Posts 2/08 | |
| iceman322 Member 15 Posts 8/14 | |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | However, one of the points of this thread was to alert people to the difference between everyday "ransomware" threats, that can be beaten and your computer restored (I do it all the time for people), as opposed to the relatively new very malicious brand of "ransomware" that has slowly encrypted your entire computer before the threat notice is given and access to your computer has been denied -- which you CAN'T fix, because you don't have access to the encryption key(s). Wahine's post above yours dealt with the old-school ransomware that you CAN defeat and restore your computer to functionality. Pringles' post above yours offers some new hope in dealing with the new encryption-style ransomware threats. So, let's be sure not to confuse the differing types of ransomware threats. |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | By NATHANIEL POPPER JULY 25, 2015 In the old days, criminals liked their ransom payments in briefcases full of unmarked bills. These days, there’s a new preferred method for hostage takers: the virtual currency Bitcoin. In a modern day version of a mob shakedown, hackers around the world have seized files on millions of computers, taken down public websites and even, in a few cases, threatened physical harm. The victims — who have ranged from ordinary computer users to financial firms and police departments — are told that their only way out is through a Bitcoin payment that is sometimes more than $20,000. One set of attackers, believed to be based in Russia and Ukraine, collected about $16.5 million in Bitcoins in a little over a month, primarily from victims in the United States, according to the security firm Sophos. Criminals like the virtual currency because it can be held in a digital wallet that does not have to be registered with any government or financial authority — and because it can be easily exchanged for real money. At the moment, a single Bitcoin can be sold online or on the street for around $290. ![]() “The criminal underground very much likes Bitcoin,” said Curt Wilson, a senior threat intelligence analyst at Arbor Networks. “It’s enabled a greater sense of obfuscation.” Bitcoin, which was released by an anonymous creator in 2009, has recently been gaining mainstream appeal. Start-ups in the industry have won investments from big names like Goldman Sachs and the New York Stock Exchange, which have praised the technology as a faster, more efficient way to complete financial transactions. But the proliferation of ransom demands has provided an unhappy reminder of the virtual currency’s continuing appeal to the criminal underworld, long after the authorities shut down the online drug bazaar, Silk Road, where heroin and cocaine were sold using Bitcoin. The latest reminder of Bitcoin’s underbelly came last week with the arrest of two Florida men. The authorities said victims of malware were steered to Coin.mx, a site run by the two men, to buy the Bitcoins to pay the ransom demanded by the malware. The complaint suggested that the criminals also used the site to launder their proceeds. In a separate set of recent cases, security experts said, several financial firms have been attacked by a criminal, or circle of criminals, going by the name DD4BC, who have threatened to overwhelm the firms’ public websites with message traffic unless a Bitcoin payment was made. These corporate victims are generally asked to pay about $10,000, the security experts said, and the attacks have shown no signs of abating. “Do not ignore me, as it will just increase the price,” DD4BC said in one email that was made public. “Once you pay me you are free from me for the lifetime of your site.” Ted Weisberg, the president of the brokerage firm Seaport Securities, which was hit in June, said that he initially thought the message was a joke. But as he called competitors, he said, he quickly learned that the threat was real. Seaport’s website ended up being down for a day and a half. Mr. Weisberg’s firm did not pay the ransom and repelled the bombardment of traffic with the help of one of its technical providers. The extortion attempts have been widespread enough that the brokerage industry’s self-governing regulatory agency, the Financial Industry Regulatory Authority, warned its members in June to contact the F.B.I. if they received a message from DD4BC. Ransom payments entered the digital world long before Bitcoin came on the scene. Previously, though, the methods for paying attackers could be cumbersome and risky for the extortionist. A credit card payment or bank transfer could easily be traced by the police, so the victims were usually asked to buy prepaid cards like Green Dot’s MoneyPak. Partly because of their use by swindlers, these cards were recently taken off the market. Bitcoin has made the delivery of ransom more seamless and untraceable for criminals because the virtual currency system is run by a decentralized network of computers that collects no personal information about users. Unlike the days of bulging briefcases, Bitcoin payments can be made without an in-person meeting. What’s more, Bitcoin transactions are designed to be irreversible, so victims cannot reclaim their money as they could with a credit card or PayPal transaction. Early Bitcoin users quickly realized that the currency could be useful for ransom payments. But in late 2013, the threat spread far beyond the virtual currency community when the first version of Bitcoin-fueled ransomware, known as CryptoLocker, began to spread around the globe. The software encrypted all of the files on a computer and offered a key to unlock the files in exchange for a Bitcoin payment. Victims were directed to several websites where they could buy Bitcoins through a bank transfer. When an alliance of international authorities took down CryptoLocker in mid-2014 and identified the mastermind as a 30-year-old Russian named Evgeniy Bogachev, the group said that the software had spread to 234,000 computers. Since then, much more virulent strains have popped up, most of them under the name CryptoWall, and spread even more widely to the computers of anyone who opened infected attachments. The authorities have had trouble estimating the number of victims because many do not report their problem and quietly pay the price. But in late 2014, Dell SecureWorks said CryptoWall had infected over 800,000 computers. New versions of the malware, going by names like TorrentLocker and Dirty Decrypt, have popped up frequently since then. A police department in Durham, N.H., that was hit by CryptoWall in June 2014, refused to hand over the ransom and was able to revert to backup files. But more recently, police departments in Dickson County, Tenn., and Tewksbury, Mass., have said that they chose to pay the roughly $500 ransom rather than deal with the headache of trying to circumvent the hackers. Beyond these attacks, extortionists went after two longtime Bitcoin advocates last year, threatening to exploit personal information about the men’s families if they did not pay up. When one of the men, Hal Finney, refused to submit, the assailant called the local police and reported a murder at Mr. Finney’s home, resulting in a SWAT team taking over the home, the family has said. The other victim, Roger Ver, threw off his attacker by offering a Bitcoin bounty of roughly $20,000 for his attacker’s arrest. Some leaders in the Bitcoin community have suggested potential ways to fend off the ransom threats, digitally marking any coins used for ransom payments, similar to how dollar bills used in hostage situations are marked with invisible dye. But such solutions have been held up because of the value that many Bitcoin believers have put in the virtual currency’s unfettered free movement. |
| privatepuppet New Member 1 Posts 2/16 | wow. would it help me to kill that nasty damned cryptolocker 2015 http://nabzsoftware.com/types-of-threats/cryptolocker? hope it will |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | Still, I would strongly advise getting and running it, as it will help -- at least as a "second opinion" -- in cleaning your computer of other things, and in cleaning-up after you have used something capable of removing Cryptolocker. Here is the new URL needed for getting VIPRE PC Rescue: http://www.vipre.com.au/Help/VIPREPCRescue.aspx BTW, have you tried doing a system restore? If you haven't had the Cryptolocker malware that long, you just might be able to take your computer back a few days to a "pre-infected" state, then rebuild only a few days? If you can recover your computer this way, be sure to run VIPRE PC Rescue immediately. FYI, download the VIPRE PC Rescue to a USB flash drive, boot your computer in Safe Mode, then launch VIPRE PC Rescue on/from the flash drive. |
| Pieps Senior Member Honey, come quick, somebody on the internet is wrong! 9233 Posts 11/13 | |
| ninja1 Senior Member 2939 Posts 1/08 | Back up all your critically important data (anything you can't afford to lose and any irreplaceable things you really care about) on external hard drive or cloud or flash drive or anywhere away from and disconnected from your computer. Have on hand whatever necessary software for restoring your operating system if need be, on CD/DVD disk or USB flash If you have those things taken care of, even if the world's worst monster-virus strikes, you just call it a total loss, but you have the necessary ingredients to rebuild/reconstitute your system anew. |
| Use the code below to link to this topic or a specific post. |
| URL of this thread |
| Link to this post with HTML |
| Link to this post with Forum Code |