Endpoint
12/12/2016
08:00 AM
100%
0%

Pay Ransom Or Infect Others!

Still under development, new ransomware will ask victims to free their files by paying 1 bitcoin or by infecting two others.

The ransomware world appears all set to get even more malicious as a new under-process malware has been discovered on the Dark Web which, when completed, will have a “novel and nasty twist” to it, reports Threatpost. Dubbed Popcorn Time, the ransomware will give its victims an option – pay 1 bitcoin to get your decryption key or infect two other people to get your decryption key. The ransom deadline will be one week.

The malware is reportedly being developed to target 500 file types and will employ AES-256 encryption to freeze files with .filock extension, Threatpost says. 

“I have never seen anything like this in ransomware. This is definitely a first,” says Lawrence Abrams of BleepingComputer.com. “There is unfinished code in the ransomware that may indicate that if a user enters the wrong decryption key four times, the ransomware will start deleting files,” he adds.

Developers of Popcorn Time claim to be students from Syria who say the money received will be used to provide relief to people of the war-ravaged country.

Read details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Nanireko
50%
50%
Nanireko,
User Rank: Apprentice
12/14/2016 | 9:39:33 AM
Popcorn Time
If you infect your friends, they can infect you too later + if all start to massively infect others, ransomware authors will have to close their business and plenty of people will demand free decryption keys.
Crypt0L0cker
50%
50%
Crypt0L0cker,
User Rank: Apprentice
12/13/2016 | 3:24:21 AM
Re: Popcorn Time ransomware
I have really big doubts that they are Syrian students. Looks like the next step of social engineering - make a victim to sympathize the crooks.
jjcouch
50%
50%
jjcouch,
User Rank: Author
12/12/2016 | 10:32:18 AM
And it continues...
Unfortunately, I think these evolutionary changes to ransomware will continue until a more thorough preventitive solution can be developed. I'd be interested to read more on their infection method: whether by phishing or drive-by downloads or other.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
5 Security Technologies to Watch in 2017
Emerging tools and services promise to make a difference this year. Are they on your company's list?
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.