FBI warns of joint threat by ransomware and banking Trojan
Posted on 31.05.2012
The combination of the Citadel banking Trojan and Reveton ransomware that Trusteer warned about at the beginning of May is apparently still targeting users.

So much so, that the FBI’s Internet Crime Complaint Center (IC3) has issued an alert explaining the details of the threat.

The victims are lured to a compromised website where they unknowingly get infected with the Citadel Trojan. The Trojan then proceeds to contact a C&C server and download the Reveton ransomware from it.

Once run, the ransomware blocks the computer and shows a warning message purportedly coming from the US Department of Justice:


It claims that the users' IP address was identified by the Computer Crime & Intellectual Property Section as visiting child pornography and other illegal content, and asks them to pay a $100 fine via Moneypack or Paysafecard in order to unblock their computer.

But even if the ransomware is removed (and it can be done without paying the "fine"), the users must be aware that until the also remove the Citadel Trojan, their personal, financial and login information can be collected and used by cyber crooks to execute identity theft and credit card fraud.






Spotlight

Chrome extension thwarts user profiling based on typing behavior

Infosec consultant Paul Moore came up with a working solution to thwart a type of behavioral profiling. The result is a Chrome extension called Keyboard Privacy, which prevents profiling of users by the way they type by randomizing the rate at which characters reach the DOM.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Wed, Jul 29th
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //