Article

Far From ‘Game Over’ for Ransomware

Jan 01, 0001

June 2014 By Zach Capers, CFE Last month, the U.S. Department of Justice, in concert with authorities from the UK, Australia, Japan, Germany, France and the Ukraine, disrupted a massive botnet named Gameover Zeus that had been the primary distributor of the notorious CryptoLocker ransomware.

June 2014

By Zach Capers, CFE


Last month, the U.S. Department of Justice, in concert with authorities from the UK, Australia, Japan, Germany, France and the Ukraine, disrupted a massive botnet named Gameover Zeus that had been the primary distributor of the notorious CryptoLocker ransomware. For nearly a year, the CryptoLocker virus has swept across the Internet, infecting more than 234,000 computers and generating an estimated $27 million in its first two months alone. Meanwhile, the Gameover Zeus network had itself amassed more than $100 million in illicit proceeds. While the success of the international effort was welcome news to Internet users everywhere, authorities were quick to warn that the criminal network could regroup and return to full strength within mere weeks.


Ransomware, as its name implies, is a form of malicious software (malware) that locks a user’s operating system and restricts access to data files until a ransom is paid. To intimidate Internet users into compliance, ransomware often employs a convincing professional interface, commonly emblazoned with police insignia or an official government logo. Messages typically consist of threatening accusations that the user has been caught viewing illegal videos, downloading pirated media or otherwise accessing forbidden Internet content, with the only remedy being to pay a fine. Other forms are far more direct and make no effort to conceal their naked attempts at extortion.


While some ransomware simply prevents access to files, other forms — known as cryptoviral ransomware (e.g., CryptoLocker) — actually encrypt users’ files. This is of particular concern to businesses due to the potentially disastrous threat of encrypted network drives. These schemes typically promise that, after payment is received, the user will be provided with a key to release the system and unencrypt files; however, even after money is transferred, the virus typically remains installed on the machine and a key is never provided.


Although some might believe they could never fall prey to such a ploy, these schemes are often well designed and incredibly successful at luring in even the most unlikely victims. For example, in November 2013, the Swansea Police Department in Massachusetts fell victim to the CryptoLocker virus and admitted to paying a ransom of $750 in an attempt to regain access to their files. Computer security experts strongly discourage ransomware victims from giving in to extortion demands and instead recommend having the virus removed if possible or, in the worst cases, simply accepting the loss of a computing device.


Ransomware goes mobile

As the global transition to Internet-enabled mobile devices has continued, writers of ransomware have rapidly adapted to take advantage of new mediums. Operating systems used with mobile devices vary greatly and, as such, securing them has thus far been a work-in-progress. Additionally, the need to secure mobile devices has not been communicated to users with the same urgency as has the need to secure traditional computing devices such as laptops and personal computers. Internet security firm Symantec published a report earlier this year predicting that increased mobile ransomware attacks will be “enabled by the now ubiquitous bring-your-own-device phenomenon coupled with the relative immaturity of mobile security technology.”


Ransomware typically appears in the form of a Trojan virus that surreptitiously infects a user’s device via a pop-up ad, banner ad, email attachment or malicious website. Mobile users might also be infected by following a link in a spammed text message, a tactic known as smishing. However, newer versions of the scheme continue to be reported.


Last month in Australia, thousands of people awoke to find their iPhones and iPads locked with a message displayed stating “device hacked by Oleg Pliss,” followed by a demand that the user send $50 by one of several payment options. The attacker had taken advantage of the Find My iPhone application by exploiting its “Lost Mode” to remotely lock users’ phones. As the attacks were localized to Australia, many suspect that the scheme was the result of a database breach that might have exposed countless people’s passwords, many of whom likely use the same password for various applications including the Find My iPhone service.


Users of Apple products such as the iPhone and iPad have historically been immune from many of the security struggles of other computer users because malicious code has generally been geared toward Windows-based computers, which have the largest number of users; however, as the popularity of Apple products has grown, their users have been increasingly subjected to various forms of cyberattacks.


While various forms of ransomware have been around since 1989 when the infamous PC Cyborg virus made its first appearance, these schemes have flourished recently due in large part to the burgeoning array of anonymous online payment services, such as CashU and Bitcoin. Cyber criminals can take advantage of these services to make easy profits while maintaining a safe distance from their crimes.


Mitigating the risks

There are several measures that can be taken to reduce exposure to ransomware and related threats, including:


Ensure that all software is kept up to date.

Be wary of suspicious emails, and use caution when clicking links or downloading attachments.

Prevent the launch of executable files from emails.

Use a reliable antivirus program that also protects against spyware.

Ensure that all important files are backed up frequently.

Use a pop-up blocker. If an unwanted pop-up does occur, close it using a keyboard command rather than clicking on the actual dialog box.

Change passwords regularly and use different passwords for all websites.

Educate employees about Internet threats and preventative measures.

If ransomware is encountered, do not send money; do file a report with the FBI’s Internet Crime Complaint Center.


Ransomware schemes are becoming increasingly sophisticated, exploiting new avenues and taking on new forms. CFEs can play a crucial role in spreading awareness and guarding against these attacks by staying informed of the latest ransomware tactics and preventative measures.