• On CHOW: Public transit snacking: yes or no?

May 24, 2005 11:16 AM PDT

Miscreants encrypt files, hold them for ransom

In a new type of online attack, extortionists remotely encrypt user files and then demand money for the key to decode the information.

In a case documented by San Diego-based Web security company Websense, the attack occurs after a user visits a Web site containing code that exploits a known flaw in Microsoft's Internet Explorer Web browser. The flaw is used to download and run a malicious program that in turn downloads an application that encrypts files on the victim's PC and mapped network drives, according to Websense. The program then drops a ransom note.

Even though this type of attack is not widespread at this point, Internet users should be aware of the threat, said Oliver Friedrichs, a senior manager at Symantec Security Response. "It is certainly concerning. This is the first time that we have seen cryptography used in this type of attack to hold your information hostage," he said.

"I would see this as the equivalent of somebody coming into your house, putting your valuables in a safe and not telling you the combination," Friedrichs said.

Researchers at Symantec have seen the malicious program used in the ransom attack. The "Trojan.Pgpcoder" searches a victim's hard disk drive for 15 common file types, including images and Microsoft Office file types. It then encrypts the files, removes the originals and drops a note asking $200 for the encryption key, Friedrichs said.

A Websense customer fell victim to the attack. Luckily, in this case the encryption wasn't very sophisticated and Websense was able to decode the customer's files, said Dan Hubbard, senior director of security and research at Websense. "In this case we could help, but every variant can be different," he said.

Attackers could use e-mail, a Web site, or other means to distribute the Trojan.Pgpcoder and launch a widespread extortion campaign, Symantec's Friedrichs said.

Websense, however, doesn't see a trend yet. Attackers leave a trail if they ask for money, Hubbard said: "This type of attack is not that difficult to perform. However, in order to collect money the attackers are leaving themselves open to investigation and tracing."

For protection, users should run security software and make sure that their software is patched, Websense and Symantec said. The Internet Explorer flaw exploited to attack the user in the Websense case was patched in July last year.

The Websense customer was victimized two weeks ago. The Web sites involved in the attack have since been taken down.

See more CNET content tagged:
Websense Inc., Symantec Corp., attack, attacker, victim

Add a Comment (Log in or register) 16 comments
Does this affect Macs?
by May 24, 2005 1:17 PM PDT
... I didn't think so. Thanks.
Reply to this comment View reply
Another reason NOT to use IE
by wazzledoozle May 24, 2005 5:20 PM PDT
This is the true drive by attack.
Reply to this comment
The obvious solution
by May 24, 2005 10:45 PM PDT
It is odd that the article doesn't even mention the most obvious
solution to this problem: BACKUP ALL IMPORTANT FILES.
Preferrably to a removable media like CD-R or DVD-R. Then when
the file is hosed (by mistake or maliciously) you can just grab the
backup and laugh at the intruders.

Oh, and death penalty for Trojan/Virus writers may help curb some
of the little creeps as well.
Reply to this comment View reply
Miscreants_Encrypt_Files - Earlier Experience
by Transaction7 May 25, 2005 3:58 AM PDT
I encountered such an encryption attack at my law office several years ago, in which different files on the same hard drives and floppy disks were encrypted with diferent programs. That time, we discovered that, on the same hard and floppy diesk, certain files had been converted from WordPerfect 5.1 (DOS) to WordStar 4, Navy DIF, and other programs for which we had no software. This did involve an old-fashioned burglary, though the local police insisted it had not and that this had resulted from a power surge!

We later learned who had done this, and recovered some paper files he had also stolen, after the statute of limitations had run. He had been recommended highly to us by lawyers, a judge, and a university department head, etc. His father found and returned some stolen hard copies of documents, as well as finding the newsletter addressed and mailed to the culprit by a national organization of child molesters. Two credible people have identified him as the perpetrator of sex crimes against them, but, in the local legal environment, wouldn't report it.. He has two college degrees and may now be practicing law somewhere but I have not found him on line yet. I will provide his name to anyone with a legitimate investigative need.

PETER S. CHAMBVERLAIN
1309 Hunt Street
Commerce, Texas 75428-2916
peterschamberlain@earthlink.net
(903)886-2323
CELL: (903)366-6926
Reply to this comment
HA HA
by May 25, 2005 6:37 AM PDT
I laugh when something happens to someone's 'critical files', the first question I ask is: 'Did you have it backed up?'

99% of the time in a non-corprate enviornment the answer is: 'Back up?' 'How was I supposed to do that?'

90% of the people I ask in a corporate enviornment say 'No', even though they have mapped network drives to personal space on a server that is backed up nightly. On a side note those same users have absolutely nothing on thier network drives.... everything is saved under my documents.....LOL

I do not feel sorry for anyone that is affected by these sorts of attacks, because if you'd had anti-virus with updated definitions and used the microsoft firewall, you'd be protected.

And to all those of you who would say 'Microsoft sucks! I never get attacked':

Well Microsoft is the big guy on top of the hill and everyone wants to take him down so they can be 'king of the hill', what they fail to realise is that as soon as someone else takes over that spot, they will become the primary target for attack. Lots of people proudly walked around saying I don't have problems now because I use FireFox....I think a virus about a week later shut those people up. Every piece of software is going to have a vulnerability reguardless if it's open source or proprietary.

I'm more in love with Microsoft than my own wife! Microsoft has provided me with the tools and knowledge I need to be successfull in this crazy world we live in. My wife just nags about her allowance and other mindless drama that wives talk about while I'm out bringing home the bacon so to speak.
Reply to this comment
Another "half-of-the-story" story
by aabcdefghij987654321 May 25, 2005 6:47 AM PDT
Which flaw in IE? Is there a patch for the flaw that the victim has failed to install?

These are questions that should be answered in the story but lazy reporters obviously don't care.
Reply to this comment View reply
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right