Confirm Action

Are you sure you wish to do this?

Confirm Cancel
Member Login

Posted: 5/24/2005 6:44:59 PM EDT


Hackers holding computer files 'hostage'

By Ted Bridis, Associated Press

WASHINGTON — Computer users already anxious about viruses and identity theft have new reason to worry: Hackers have found a way to lock up the electronic documents on your computer and then demand $200 over the Internet to get them back. (Related item: Inexpensive, common sense moves by businesses could prevent data theft)

Security researchers at San Diego-based Websense uncovered the unusual extortion plot when a corporate customer they would not identify fell victim to the infection, which encrypted files that included documents, photographs and spreadsheets.

A ransom note left behind included an e-mail address, and the attacker using the address later demanded $200 for the digital keys to unlock the files.

"This is equivalent to someone coming into your home, putting your valuables in a safe and not telling you the combination," said Oliver Friedrichs, a security manager for Symantec.

The FBI said the scheme, which appears isolated, was unlike other Internet extortion crimes. Leading security and antivirus firms this week were updating protective software for companies and consumers to guard against this type of attack, which experts dubbed "ransom-ware."

"This seems fully malicious," said Joe Stewart, a researcher at Chicago-based Lurqh Corp. who studied the attack software. Stewart managed to unlock the infected computer files without paying the extortion, but he worries that improved versions might be more difficult to overcome. Internet attacks commonly become more effective as they evolve over time as hackers learn to avoid the mistakes of earlier infections.

"You would have to pay the guy, or law enforcement would have to get his key to unencrypt the files," Stewart said.

The latest danger adds to the risks facing beleaguered Internet users, who must increasingly deal with categories of threats that include spyware, viruses, worms, phishing e-mail fraud and denial of service attacks.

In the recent case, computer users could be infected by viewing a vandalized Web site with vulnerable Internet browser software. The infection locked up at least 15 types of data files and left behind a note with instructions to send e-mail to a particular address to purchase unlocking keys. In an e-mail reply, the hacker demanded $200 be wired to an Internet banking account. "I send programm to your email," the hacker wrote.

There was no reply to e-mails sent to that address Monday by The Associated Press.

FBI spokesman Paul Bresson said more familiar Internet extortion schemes involve hackers demanding tens of thousands of dollars and threatening to attack commercial Web sites, interfering with sales or stealing customer data.

Experts said there were no widespread reports the new threat was spreading, and the Web site was already shut down where the infection originally spread. They also said the hacker's demand for payment might be his weakness, since bank transactions can be traced easily.

"The problem is getting away with it — you've got to send the money somewhere," Stewart said. "If it involves some sort of monetary transaction, it's far easier to trace than an e-mail account."
Link Posted: 5/24/2005 7:03:45 PM EDT
Link Posted: 5/24/2005 7:14:38 PM EDT
I would happily be the trigger man for capital punishment of these fucking scumbags.
Link Posted: 5/24/2005 7:17:48 PM EDT

Nice...... This fucker will be in jail soon, when they find him.

eRansom What the fuck's next....


Link Posted: 5/24/2005 7:24:05 PM EDT
How about idiot Lusers learn more about the box sitting on their desk, and not let programs like this onto their system in the first place?

A PC is not an appliance.

I haven't had one case of spyware other than a cookie or two in over a year.

And it's not for a lack of trying, believe you me.
Link Posted: 5/24/2005 7:24:41 PM EDT
As a computer dork: That's AWESOME.

As a human being: I hope they catch them and they get raped in prison.
Link Posted: 5/24/2005 7:46:29 PM EDT
I hear these guys have solved the problem:
Link Posted: 5/24/2005 8:31:11 PM EDT

"You would have to pay the guy, or law enforcement would have to get his key to unencrypt the files," Stewart said.

...Or revert to the backup copy that you made last week, and tell the extorter to go f*ck himself -
Top Top