Slashdot Mirror


Many Australians Forced To Pay For "Unbreakable" Cryptolocker Ransomware

An anonymous reader writes: Australians are paying thousands of dollars to overseas hackers to rid their computers of an unbreakable virus [Cryptolocker]. The deputy chairwoman of the Australian Competition and Consumer Commission, Delia Rickard, said over the past two months there had been a spike in the number of people falling victim to the scam. The commission has received 2,500 complaints this year and estimates about $400,000 has been paid to the hackers. Bad news for Australians: this is just one of many targetting the country.

3 of 148 comments (clear)

  1. Every customer of mine by dwywit · · Score: 4, Interesting

    Gets Cryptolocker installed. Via Group Policy, it prevents, among other things, anything being executed from the user's temp directory/ies - which is where email attachments are placed for whatever operation they require - picture preview, etc. It's not a guarantee, but it presents a big obstacle to any attacker attempting to fool a user into executing their code simply by opening an email.

    Not affiliated, just a happy user.

    --
    They sentenced me to twenty years of boredom
    1. Re:Every customer of mine by Billly+Gates · · Score: 4, Interesting

      It can still get on via angler malware kit. The type from yahoo.

      It is run only from ram making it impossible to block or detect.

  2. One client has fallen for it four times by Gumbercules!! · · Score: 4, Interesting

    I know someone who personally accounts for 4 of those installations. On the same computer. Because she's fallen for the same frikkin scam four times. Every time I ask her "why did you open an email claiming to be from the IRS, when we don't have an IRS in Australia", she tells me "because it sounded real". You should see the grammar in these scam emails, too: they're written like "please effective the transactionments with the rapid or we can has your cheeseburgers". Yet she's still fallen for it. Four. Times.

    Fortunately, I back that site up effectively.