This ransomware sneakily infects victims by disguising itself with antivirus software
#1
Quote:A successful family of ransomware which has been terrorising organisations around the world has been updated with a new trick to lure victims into installing file-locking malware: posing as anti-virus software.
 
The group behind Dharma regularly look to update their campaigns in order to ensure the attacks remain effective and they have the best chance of extorting ransom payments in exchange of decrypting locked networks and files of Windows systems.
 
Now the cyber attacks have evolved again and cyber security researchers at Trend Micro have detailed a new means of the Dharma being deployed: by bundling it inside a fake anti-virus software installation.
 
Like many ransomware campaigns, Dharma attacks start off with phishing emails. The messages claim to be from Microsoft and that the victim's Windows PC is 'at risk' and 'corrupted' following 'unusual behaviour', urging the user to 'update and verify' their anti-virus by accessing a download link.

If the user follows through, the ransomware retrieves two downloads: the Dharma ransomware payload and an old version of anti-virus software from cyber security company ESET.

When the self-extracting archive runs, Dharma begins encrypting files in the back round while the user is asked to follow installation instructions for ESET AV remover – the interface is displayed on their desktop and requires user interaction during the installation process, acting as a distraction from the malicious activity.

Once the installation is complete, the victim will find themselves confronted with a ransom note, demanding a cryptocurrency payment in exchange for unlocking the files.

SOURCE: https://www.zdnet.com/article/this-ranso...-software/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, Mohammad.Poorya
Reply


Messages In This Thread
This ransomware sneakily infects victims by disguising itself with antivirus software - by silversurfer - 09 May 19, 12:57

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
NanaZip 6.0 Update 7 (6.0.1711.0)
NanaZip 6.0 Update...harlan4096 — 06:10
Vivaldi 7.9 Build 3970.64
Vivaldi 7.9 Build ...harlan4096 — 06:09
Thunderbird 150.0.2 & Thunderbird 140.10...
Thunderbird 150.0....harlan4096 — 06:08
Brave v1.90.121 (Chromium 148.0.7778.96)
Release v1.90.121 ...harlan4096 — 06:07
QOwnNotes
26.5.6 Note folde...Kool — 06:07

[-]
Birthdays
Today's Birthdays
avatar (39)omapek
avatar (48)Geraldtuh
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (45)talsmanthago
avatar (31)mocetor
avatar (46)piomaibhaict
avatar (51)kingbfef
avatar (38)izenesiq
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (41)axylisyb
avatar (44)tukrublape
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>