Ransomware: The Latest Trend in Malware

Analysis
Mar 21, 20122 mins

The bad guys are now pretending to take your PC hostage. Don't pay the ransom.

If the software industry showed as much innovation and initiative as the malware business, we might have some really nice software to choose from. But for now, the bad guys are one step ahead of the rest of us, with a new way to squeeze money out of your pocket.

Microsoft calls this new trend ransomware, and it looks a lot like older scams in which an app masqueraded as an antivirus program and then tried to sucker you into buying a useless piece of software to remove an infection that doesn’t exist.

In the case of ransomware, an infection takes control of and holds hostage an infected machine, locking the user out until a payment of some form is made. In one case, Microsoft found an example that looked like an official Microsoft screen, claiming the Windows license was invalid.

Others used artwork from legitimate organizations when they were in fact not affiliated. These have included the German Federal Police, GEMA (Germany’s performance rights organization), the Swiss Federal Department of Justice and Police, the UK Metropolitan Police, the Spanish police and the Dutch police.

The ransomware locks the computer, displays the alert screen and demands the payment of a “fine” for the supposed infraction through a legitimate online payment service like Paysafecard or Ukash. Since many of these infections are taking place in Europe, Paypal does not seem to be involved.

Many of these infections are distributed through drive-by downloads on websites that use the Blackhole Exploit Kit, a popular kit for other drive-by infections. This comes through redirects to malicious websites or through exploits in vulnerabilities. The Blackhole Exploit Kit looks to see if a number of known vulnerabilities are unpatched on the system. Fortunately, none of them are zero-day, so there are no excuses for not running Windows Update.

Andy Patrizio is a freelance journalist based in southern California who has covered the computer industry for 20 years and has built every x86 PC he’s ever owned, laptops not included.

Andy writes the Data Center Explorer blog for Network World. His work has appeared in a variety of publications, including Tom's Guide, Wired, Dr. Dobbs Journal, Tech Target, Business Insider, and Data Center Knowledge. Earlier in his career, he held editorial positions at IT publications like InternetNews, PC Week and InformationWeek.

Andy holds a BA in Journalism from the University of Rhode Island.

More from this author