📜 ⬆️ ⬇️

NRansom Locker extorts nude pictures



For years, cryptographers encrypted files on a computer and extorted money for decrypting them. But not all attackers need money. Researchers from MalwareHunterTeam discovered a strange kind of crypto-fiber called nRansom, which for accessing files does not require money, but “a minimum of 10 nude photos” of the victim. Obviously, malefactors believe that pretty blondes are their victims. And if not?

In fact, nRansom is not a cryptographer, but a blocker, that is, it does not encrypt files, but simply blocks the download of the computer. As you know, getting rid of this virus is not difficult, although some blondes may not understand.

The malware displays a text message (see above) that the only way to regain access to a computer is to send naked photos, at least ten of them. After this verification will be carried out that the photos really belong to the victim (it is not clear how, perhaps, they will offer to be photographed against the background of the screen with the infected computer). As soon as verification is completed, the unlock code will be sent to the victim. Malefactors honestly say that they will sell these photos in the darknet later. Still, they need money.
')
You can’t help out a lot for nude photos, so these are kind of criminals. On the other hand, from the side of the victim, making pure selfies is technically much easier than looking for a way to transfer Bitcoins to the specified address. There generally can not have money, so that the range of potential victims is expanding many times.

A sample of malicious code nRansom published in the database VirusTotal. At the moment, the crypto-fiber was met only in the form of the file nRansom.exe, which runs under Windows. If any of your friends will suffer such a misfortune, advise you to press the keys Ctrl + Alt + Shift + F4, and after booting the system run the antivirus.

Source: https://habr.com/ru/post/373829/


All Articles