welcome

This website uses cookies to ensure you get the best experience on our website.
Please scroll to the bottom of page to read the notice if you are coming from the European Union...

Sunday, August 28, 2016

New Ransomware Poses As A Windows Update (hothardware.com)

An article from Hot Hardware: 


A security researcher for AVG has discovered a new piece of ransomware called Fantom that masquerades as a critical Windows update

Victims who fall for the ruse will see a Windows screen acting like it's installing the update, but what's really happening is that the user's documents and files are being encrypted in the background...

The scam starts with a pop-up labeled as a critical update from Microsoft.


 Once a user decides to apply the fake update, it extracts files and executes an embedded program called WindowsUpdate.exe... 

 As with other EDA2 ransomware, Fantom generates a random AES-128 key, encrypts it using RSA, and then uploads it to the culprit. 

From there, Fantom targets specific file extensions and encrypts those files using AES-128 encryption... 

Users affected by this are instructed to email the culprit for payment instructions.
 
While the ransomware is busy encrypting your files, it displays Microsoft's standard warning about not turning off the computer while the "update" is in progress.

 Pressing Ctrl+F4 closes that window, according to the article, "but that doesn't stop the ransomware from encrypting files in the background."

***

A lot of Windows users migrated to Apple products with the Windows Ten release.

Now there will most likely be another  surge in migration.

Some businesses that have relied on Windows OS have gotten frustrated and migrated.

Now businesses using Windows will be crippled if this "Fantom" hits their machines.

Preemptive migration to Apple computers would be expected if a fix doesn't appear soon. 


No comments:

Post a Comment