Breaking Bad ransomware is not detected by VirusTotal

Η security Heimdal Security revealed a new ransomware campaign, which, to date, remains unrecognized by any of the 57 the security found in Google's VirusTotal antivirus aggregator.Ransomware

The new ransomware spreads to Scandinavia using spam emails, which come with a Word document attached. This file is trapped with a malicious macro that, when the document opens, executes and downloads the ransomware on the victim's computer.

Όταν κατέβει το ransοmware κρυπτογραφεί άμεσα τα σημαντικότερα έγγραφα του χρήστη, και αλλάζει την κατάληξη των αρχείων σε ".breaking_bad".

Access to encrypted is impossible unless their owners pay the ransom.

The Word macro that το ransοmware, έχει χρησιμοποιηθεί επίσης και από μια κινεζική ομάδα which targeted Russian military bases.

The reason why this technique is so dear to hackers is because it allows them to create malicious files that do not seem to be malicious at all.

This is probably the reason why ransomware is not detected by VirusTotal.virustotal

Τα έγγραφα του Word μοιάζουν με οποιαδήποτε άλλα έγγραφα του Word, και δεν περιέχουν κάποιο κακόβουλο φορτίο, εκτός από μερικές οδηγίες "για να κατεβάσουν ένα αρχείο από το Web" από ένα macro.

This file can be anything: an image, a CSS file, or a malware. So the only way to protect against such threats is to educate users not to open any files on the Internet that come from unknown people, even if they promise.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).