Archived Blog

New Cyber Extortion / Ransomware.

03.13.2006 - 4:41 AM
Last week we received an interesting call from an IT administrator who found that their companies files were "being held hostage". The situation was very similar to other cyber extortion attacks that we have seen in the past, where users files are encoded, encrypted, or password protected and there is a message left on the machine with instruction on how to get them back. In all cases the file requests that the user sends them money via EGold. In this case the user believes that one of their users was most likely infected by visiting a malicious website.

Websense Security Labs original discovery: http://www.websensesecuritylabs.com/alerts/alert.php?AlertID=194

On Saturday Lurhq released an analysis of this new piece of malicious code (http://www.lurhq.com/cryzip.html).

Websense CPM customers are protected from this newest piece of cyber extortion malicious code (AKA "ransomware") as are customers who subscribe to the security Premium Group and Security Suites from connected to sites infected with malicious code.

Bookmark This Post: