New ransomware lures victims by pretending to be a Canadian Government COVID-19 tracing app

2020-6-27 15:42

The fraudulent websites encrypt data from victim’s android devices, ESET revealed

New ransomware called CryCryptor has been targeting Android users in Canada under the premise of being an official COVID-19 tracing app — according to research published by ESET on Wednesday.

The ransomware, distributed via two fraudulent government-backed websites, encrypts personal data from the victims’ devices. ESET’s researchers have analysed the ransomware and developed a decryption tool for victims. The cybersecurity company has also informed the Canadian Centre for Cyber Security upon discovery and identification of the ransomware.

According to ESET, the fraudulent websites claimed to be an initiative by Health Canada to aid in contact tracing once a patient has been declared as COVID-19 positive. Interestingly, the websites appeared a few days after an official announcement by the Canadian Government to back the development of a nation-wide contact tracing app called COVID Alert.

The app is set to be rolled out for testing in Ontario and has not been officially launched. Scammers took advantage of the announcement by Canadian authorities to lure victims into believing the authenticity of the website.

The hackers work to encrypt the files on the victim’s device and instead of locking the device, it leaves a “readme” file with the attacker’s email in every directory with encrypted files, ESET reported. The files are encrypted using AES with a randomly generated 16-digit key. Once CryCryptor encrypts a file, it removes the original file and replaces it with three new files. These displays a notification “Personal files encrypted, see readme_now.txt”.

The ransomware network caught the eye of the ESET researchers when a tweet identifying a ‘malware’ on the supposedly official website was put out by a user. The cyber-security company then analyzed the app and discovered an “ a bug of the type ‘Improper Export of Android Components’ that MITRE labels as CWE-926,” the official announcement said. This bug allowed ESET researchers to develop an app that launches the decrypting functionality built into the ransomware app by its creators.

The CryCryptor ransomware is based on an open-source code available on GitHub. ESET researchers have stated that the developers of open-source ransomware, who named it CryDroid, were aware of it being used for malicious purposes and falsely tried to disguise it as a research project.

“We dismiss the claim that the project has research purposes – no responsible researcher would publicly release a tool that is easy to misuse for malicious purposes,” the announcement stated. “We notified GitHub about the nature of this code,” it added.

The post New ransomware lures victims by pretending to be a Canadian Government COVID-19 tracing app appeared first on Coin Journal.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Time New Bank (TNB) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.01 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Цена в час новости $ 0.0041889 (-100%)

new ransomware government tracing canadian app covid-19

new ransomware → Результатов: 67


Фото:

Vicious malware threatens to turn search engine into crypto-mining zombie botnet

Enterprise search engine Elasticsearch is under threat of being turned into a sophisticated cryptocurrency mining botnet to be used in distributed denial of service (DDoS) attacks. Cybersecurity firm Trend Micro describes a new malware strain that launches multi-stage attacks on publicly accessible databases and servers that run old versions of Elasticsearch software.

2019-7-23 17:54


Фото:

New York City College Struck by Ransomware, $1.9 Million in Bitcoin Demanded

Munroe College in Manhattan has been hit by a ransomware attack that has shut down the college’s computer systems. The hackers are demanding 170 bitcoin (BTC), which is roughly $1. 9 million. The malware infection came to light on the morning of July 10, but the specifications of the infection are still largely unknown, as reportedRead MoreRead More.

2019-7-15 13:00


Фото:

Ransomware Stems From Governments, But Bitcoin Gets The Blame

When hackers paralyzed the city of Baltimore with a ransomware attack last month, the focus became not the theft itself, but a $76,000 Bitcoin ransom. NSA Passes Ransomware Buck According to a recent report from The New York Times, a ransomware attack in Baltimore, Maryland in May was empowered by the use of a stolen National Security Agency (NSA) cyberweapon.

2019-6-9 19:01


Фото:

Hackers Seeding Ransomware via Bitcoin and Ether Giveaways

While the entire cryptospace is busy celebrating the return of the “bulls,” bad actors have formulated a new scheme aimed at stealing victims’ cryptos and injecting ransomware into their systems. These hackers are now using several websites to push their fake bitcoin (BTC) and ether (ETH) giveaway programs, according to a Bleeping Computer report onRead MoreRead More.

2019-5-28 13:00


Фото:

Watch out for this new cryptocurrency ransomware stalking the web

Researchers have discovered “Anatova”, a brand new family of cryptocurrency-fuelled ransomware, and they warn it has the potential to become outright dangerous. Cybersecurity firm McAfee explained Anatova hides in seemingly innocuous icon files – usually the same popular games or applications – in order to fool the user into downloading the malware.

2019-1-23 19:58


Фото:

Pirated Content and Software Drives Malicious Crypto Mining, Says New Report by Kaspersky Lab

Cryptocurrency mining malware attacks, which infected over five million people in the first three quarters of 2018 alone could be entering your systems via pirated software and content. Malicious cryptocurrency mining is the biggest threat to internet users in 2018, leaving behind ransomware which had been most prevalent over the last few years.

2018-11-30 15:59


Фото:

Researchers Link NotPetya Outbreak and Kiev Power Grid Outage to one Hacking Group

Depending on how one looks at the world, coincidence is either a common thing or doesn’t exist at all. In the world of cyberthreats, it would seem the latter is the more common conclusion. New research shows the NotPetya ransomware attack, as well as a disruption of Ukraine’s power grid, are linked together by one […] The post Researchers Link NotPetya Outbreak and Kiev Power Grid Outage to one Hacking Group appeared first on NullTX.

2018-11-8 18:58


Фото:

Hackers Recycle old Ransomware for new Crypto Malware

Cybersecurity experts at Fortinet and Kaspersky have discovered new cryptocurrency malware that has been developed using updated versions of known ransomware according to September 5, 2018, reports. Cryptojacking Malware If you have been following blockchain media, you will be aware of the aggressive surge in cryptocurrency mining malware that allows hackers to implement code into a website that mines cryptocurrency...The post %%POSTLINK%% appeared first on %%BLOGLINK%%.

2018-9-10 19:00


Новый шифровальщик Ryuk принес своим создателям более $600 000 в биткоинах

В Сети обнаружен новый вирус-шифровальщик под названием Ryuk, требующий внушительный выкуп в биткоинах. Под ударом оказалось несколько компаний по всему миру, сообщают исследователи из Check Point. A new targeted attack against cooperates in Europe and USA has been taking place over the past weeks.

2018-8-23 14:25