Slashdot Mirror


New Ransomware Offers The Decryption Keys If You Infect Your Friends (bleepingcomputer.com)

MalwareHunterTeam has discovered "Popcorn Time," a new in-development ransomware with a twist. Gumbercules!! writes: "With Popcorn Time, not only can a victim pay a ransom to get their files back, but they can also try to infect two other people and have them pay the ransom in order to get a free key," writes Bleeping Computer. Infected victims are given a "referral code" and, if two people are infected by that code and pay up -- the original victim is given their decryption key (potentially).
While encrypting your files, Popcorn Time displays a fake system screen that says "Downloading and installing. Please wait" -- followed by a seven-day countdown clock for the amount of time left to pay its ransom of one bitcoin. That screen claims that the perpetrators are "a group of computer science students from Syria," and that "all the money that we get goes to food, medicine, shelter to our people. We are extremely sorry that we are forcing you to pay but that's the only way that we can keep living." So what would you do if this ransomware infected your files?

236 comments

  1. Well, then by bluegutang · · Score: 1, Insightful

    Your "friends" don't have to be human. Get two blank hard drives, or even VMs on your favorite cloud server, and make those your "friends". They will be locked forever, but you can just wipe them and not lose any data.

    Still a nasty trick though.

    1. Re:Well, then by bluegutang · · Score: 5, Insightful

      ^ Ignore previous comment, I'm a doofus who didn't carefully read the summary, much less the article.

    2. Re:Well, then by Cryacin · · Score: 3, Funny

      Pfft. Been done before on VHS.

      Phone Rings:
      Creepy voice:"Seven days..."

      --
      Science advances one funeral at a time- Max Planck
    3. Re:Well, then by donaldm · · Score: 0

      A few days ago my wife got a web warning in Chrome that all her files were encrypted so she informed me since she could not close the Web page or the browser.

      Sure enough, the Web page was locked but a quick "xkill" fixed the problem and on checking I found her files were safe. Even if her files were encrypted I could have just wiped them and recovered them from backup. So to the idiots that tried to compromise my system count to four in binary or if you can't count that high may I suggest a decent prison reform school.

      I hope you did not think I was running a Windows OS on my desktop. I think "xkill" would have been a dead giveaway. :-)

      --
      There ain't no such thing as proprietary standards only proprietary formats. Standards are by definition open.
    4. Re:Well, then by Anonymous Coward · · Score: 1

      If it was done in the browser, then there probably wouldn't have been any encryption anyway. Why go to the trouble of writing actual ransomware when you can just hijack a dodgy ad network and demand payment on a web page? A few people will probably pay up even if their files are fine and, as you discovered, fake ransomware is fully cross-platform with no extra effort.

    5. Re:Well, then by michelcolman · · Score: 1

      The two friends have to pay before your files get unlocked.

    6. Re:Well, then by Kjella · · Score: 1

      If they actually tried, there are meta-scams that don't actually do anything they just pretend to hold your files hostage. It's like robbing someone with a replica gun, if the victim can't tell and you don't try to shoot anything it works just the same. The kind of victim they're looking for with lots of high-value data and no backups is probably just going to panic and pay anyway, since it's pretty much established that there is no "fix" for a crypto-locked machine.

      --
      Live today, because you never know what tomorrow brings
    7. Re:Well, then by Anonymous Coward · · Score: 0

      I hope you did not think I was running a Windows OS on my desktop. I think "xkill" would have been a dead giveaway. :-)

      Not necessarily, but still.

    8. Re:Well, then by Anonymous Coward · · Score: 0

      So basically the whole point of your post is to show off that you're running Linux and you have backups. Congratulations on being a twat.

    9. Re:Well, then by msauve · · Score: 4, Insightful

      "So what would you do if this ransomware infected your files?"

      No, the answer is not paying a ransom, or infecting friends (or VMs). The correct answer is to reformat the storage and restore from a backup.

      --
      "National Security is the chief cause of national insecurity." - Celine's First Law
    10. Re:Well, then by Anonymous Coward · · Score: 1

      Fuck you ruined my day.

    11. Re:Well, then by Gilgaron · · Score: 1

      Yeah every now and then I'll see a full screen Chrome pop up claiming to have encrypted everything (and that they're the FBI, and can be paid via Wahlgreens gift cards or some nonsense)... someone that only knows how to use the mouse might panic, but even just turning the computer off would work so I'm not sure how they manage to fleece anyone.

    12. Re:Well, then by MitchDev · · Score: 1

      The answer is a slow, torturous, painful, publicly televised death for the perpetrators of such actions...

    13. Re:Well, then by mlts · · Score: 1

      I made the same exact mistake on another forum. I didn't see the "if the friends paid up" bit either.

      Long term, I do wonder if this might become an actual infection vector, where people try to get others to run software just to get them infected in order for them to get a decryption key, as opposed to paying ever-higher currency costs for BitCoins.

    14. Re:Well, then by Ol+Olsoc · · Score: 1

      So basically the whole point of your post is to show off that you're running Linux and you have backups. Congratulations on being a twat.

      I wonder how many Linux people have two friends to infect?

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    15. Re:Well, then by Cryacin · · Score: 3, Funny

      I wonder how many Linux people have two friends to infect?

      Necessity drives innovation.

      --
      Science advances one funeral at a time- Max Planck
    16. Re:Well, then by Anonymous Coward · · Score: 0

      Disregard that, I suck cocks.

    17. Re:Well, then by omnichad · · Score: 1

      but even just turning the computer off would work

      Not always - if you're computer illiterate and your browser is set to save state, it will come back to the same page again when you open it. (I have been asked and paid to fix this multiple times AFTER a reboot).

    18. Re:Well, then by Ol+Olsoc · · Score: 1

      "So what would you do if this ransomware infected your files?"

      The correct answer is to reformat the storage and restore from a backup.

      In a world of Password1, I wonder what the percentage is of people who actually have any backup at all. Gotta be pretty low.

      Most people are the type who used to put electrical tape over their blinking VCR lights, so backing up their computer simply doesn't happen - a combination of laziness and avoiding reading instructions.

      A friend for some crazy reason took her computer to an on-campus computer help for an update. I guess she thought I was too busy or something. Well, the Windows guy hosed her Mac. She calls me in a panic. So I went over to her place....

      "Remember that external USB drive I had you buy and told you that you had to have it plugged in while you were at home?"

      Yeah?

      "Let's plug it in and let it do it's thing."

      A little while later, Time machine had restored her computer to the way it was. She's a big believer in backups now, even though I had to almost trick her into using it.

      OSX, Linux, or Windows, back the damn things up folks. But there I go preaching to the choir again.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    19. Re:Well, then by bluefoxlucid · · Score: 0

      Actually, this looks more complex than all that.

      I've been showing people a Universal Social Security policy proposal for the United States--essentially a replacement for our current welfare system that remediates all of its failures and accomplishes the goals of our public aid and minimum wage policies, among other things. The interesting concern here is the direct welfare impact: my original target was simply to eliminate homelessness and hunger without raising taxes on anyone (the second half of that is mathematically-demonstrated; the first is theoretically-sound, but obviously as-yet-untested because it relies on humans to be predictably greedy and self-serving, and should work because there are so damned many humans that they can't all be willing to act contrary to historical human behavior).

      You might notice a commonality in considerations here:

      all the money that we get goes to food, medicine, shelter to our people. We are extremely sorry that we are forcing you to pay but that's the only way that we can keep living.

      In New York, crime studies have suggested 92% of female prostitutes claim they would stop if they believed they had enough money for food and shelter. I don't believe they would stop; instead, I figure that particular sub-population would have never gotten started, and thus the first generation who doesn't face that pressure will be less-inclined to take that action in pursuit of basic survival. In other words: if the next generation can get food and shelter without becoming hookers, 92% of the would-be hookers won't be hookers.

      It seems the economic situation in Syria has left these students with the belief that their alternatives are limited to ransomware or death. That doesn't sound all too different to me. In any case, what we have are good people who are more-willing to inconvenience others with mild robbery than they are to lay down and die.

      Does this sound familiar?

      A lot of people despise my Universal Social Security plan because it doesn't tax the rich and businesses. They demand we "make businesses pay" and "make the rich give up the money they stole", somehow. A lot of bad economics arguments crop up in those discussions; but the thrust of it is that people want to rob the rich to satisfy themselves.

      Among liberal middle-classers, you get a blunt disregard for anything that helps the poor if it doesn't hurt the rich. Among the actual poor, you get an immediate reaction that the rich must be taking everything and should be made to pay up; and, when you give the poor an alternate solution that appears to their perception to improve their lives by granting greater access to things like food, shelter, and medical care, they immediately cease to care about taxing the rich. The poor Americans who struggle for food and face the threat of eviction and homelessness blame the rich only until they see a way to meet their own needs, and then they lose interest in robbing people they think don't need all they have.

      It seems to me we have victims of an economic situation who believe that their actions create less harm for others than that which they face, and so is justified. The solution, long-term, must be an economic one; there is no justice in punishing good men who have no alternative for survival.

    20. Re:Well, then by bluegutang · · Score: 1

      Sheesh, I'm getting lots of karma both for my wrong post, and for the correction I posted to it. It's a strange world...

    21. Re:Well, then by dbIII · · Score: 1

      I don't believe they would stop

      If you look at some of the guys that walk up to those girls on the street you would believe it. It's Russian roulette with random violent psychos in some cases according to police reports.

    22. Re:Well, then by dbIII · · Score: 1

      Among liberal middle-classers, you get a blunt disregard for anything that helps the poor if it doesn't hurt the rich

      You should get out more and you'll see that your strawman is vanishingly rare.

    23. Re:Well, then by Ol+Olsoc · · Score: 1

      I wonder how many Linux people have two friends to infect?

      Necessity drives innovation.

      You don't mean........ come out..... of mom's basement?

      side note - I'm a guy who uses Linux, but loves to make fun of anyone.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    24. Re:Well, then by Anonymous Coward · · Score: 0

      so how does universal social security in the US address supposed desperate Syrian hackers blackmailing anyone? If they've got time to write and test a ransomware kit, they have time to go on elancer or other site to bid on jobs. A friend of mine got through his work by farming out pieces of a project and collect his 6 figure salary with half days and "work from home". Not unlike similar stories but he didn't give up access to the company VPN or servers.

    25. Re:Well, then by MitchDev · · Score: 1

      This guy just keeps spouting this pie-in-the-sky/Star Trekian economic "plan" in pretty much every thread...

    26. Re:Well, then by Anonymous Coward · · Score: 0

      didnt read TFA, but the quote says two friends need to PAY. so then you just need to pay double to clear your VMs. The perps dont seem to be THAT stupid.

    27. Re:Well, then by JustAnotherOldGuy · · Score: 2

      Yeah every now and then I'll see a full screen Chrome pop up claiming to have encrypted everything (and that they're the FBI, and can be paid via Wahlgreens gift cards or some nonsense)

      Lol, yes, my neighbor saw this on his Chromebook and brought it over to my place in a panic.

      I asked him if he thought the FBI really took payments, and if so, that they would take them by Western Union or iTunes cards or whatever. lol

      We closed the tab and he went back home a little bit wiser. Not much, but a little bit.

      --
      Just cruising through this digital world at 33 1/3 rpm...
    28. Re:Well, then by JustAnotherOldGuy · · Score: 1

      The answer is a slow, torturous, painful, publicly televised death for the perpetrators of such actions...

      I like this idea and would happily contribute to a Kickstarter campaign to help make it a reality.

      --
      Just cruising through this digital world at 33 1/3 rpm...
    29. Re:Well, then by Cro+Magnon · · Score: 2

      Both my friends are deadbeats. :(

      --
      Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
    30. Re:Well, then by bluefoxlucid · · Score: 1

      Actually, not really. Whenever it comes up, I get a lot of people railing against it. One of the big strawmen I keep hearing is "we need the businesses to pay," talking about minimum-wage, when I've suggested that people's income will go up over time outside of wages (and I suggest lowering payroll taxes as well). People also constantly talk about reclaiming the CEO's salary, for some reason.

      It's a highly-common response. The conservative middle-class in America more often just claims that there are billions of jobs available for everyone and the poor are too lazy to work and are all drug addicts, while simultaneously claiming Obama sent all the jobs to China or something.

    31. Re:Well, then by Anonymous Coward · · Score: 0

      Those two "friends" have to pay otherwise no free key for you.

    32. Re:Well, then by bluefoxlucid · · Score: 1

      Star Trek's economy is a post-scarcity economy where everything is free because there's basically no labor involved.

      My Universal Social Security plan assumes capitalism is the only economic behavior. People apply labor to make things, and trade their labor time to acquire other things; and people organize to minimize their effort and maximize their returns. This is called "economizing", or maximizing the ends derived from your means.

      The core concept of economy is thus profit: you seek to do little and gain much, or to "profit". Businesses thus will not create housing for the poor out of the goodness of their little NPO hearts; rather, they create housing for the poor because the act of doing so generates billions of dollars of revenue and funnels hundreds of millions of dollars of profits into the hands of landlords.

      Likewise, a competent plan to improve welfare must reduce taxes and lower government administrative overhead: it must be less-socialist than today's plan.

      So my "pie-in-the-sky/Star Trekian economic plan" is called capitalism.

      2013 taxpayer burden: $2,400 billion. 2013 Federal spending: $3,400 billion.

      2013 taxpayer burden under my plan: $1,400 billion. 2013 Federal spending: $2,200 billion.

      You can keep waving the banner of socialism all you want; I'm putting power back in the hands of the people and reducing the tax burden carried by everyone.

    33. Re:Well, then by bluefoxlucid · · Score: 1

      That doesn't mean, given merely adequate means, that they would suddenly perceive stability. To cover the fear of financial instability, they'd need means that eliminate any financial strain. These women have been trained, through long years of effort, to identify any financial trouble as lethal to their quality-of-life, and to respond by engaging in prostitution; giving ground has always been the path to homelessness, starvation, and utter self-destruction, and so they have learned an impulse to avoid any financial trade-offs by desperately seeking money instead.

      It takes more than simple money to undo that training; and a person born into freedom from that eventuality does not develop those routines of thought.

    34. Re:Well, then by Anonymous Coward · · Score: 0

      "A lot of people despise my Universal Social Security"

      I doubt we have the same definition of "a lot of people". This idea most likely toils in obscurity. I don't even count. I don't despise it, having not really read much of your comment.

    35. Re:Well, then by kaatochacha · · Score: 1

      My Dad occasionally gets these on his Mac. He calls them via Skype at the number provided, then plays the "I'm the crazy old man who can't understand anything you're trying to tell me because I'm old and hard of hearing" card.
      He enjoys it a lot.

    36. Re: Well, then by D00MSlayer · · Score: 1
    37. Re:Well, then by Anonymous Coward · · Score: 0

      He's only trolling a disposable grunt, the one person who hates the job more than you.

      We don't pay phone jockeys because they "provide a service", we pay them to be insulation. We pay them so that "cards" like yours are utterly meaningless. We pay them to sit in the line of fire, to be meatshields.

      If you can escalate your way to someone who slightly matters, then line squatting is slightly worthwhile.

    38. Re:Well, then by Anonymous Coward · · Score: 0

      I'm under the impression the middle classes overthink their wealth because of basic psychology - they're quite clearly, quite visibly wealthier than the world they know, than their surroundings, than their neighbors, than the people they know. Sure, they're aware that "there are richer" but everyone they actually know has a smaller lawn penis. This is aided by a culture that has mild taboos about displaying your actual income, that teaches we entertain a blurred line between your possessions and actual wealth - the poor have phones and the rich wear jeans, we are to remember indicators are suggestive at best, and the Next Guy only seems equally wealthy, but you're probably better off.

      With that firmly seated in their outlook, their immediate response to the idea of any wealth redistribution is "taking my money away, because I am wealthy"

      In reality they won't notice anything - they've overlooked that they'll be recipients. This illusion dips below the six-figure incomes, people who don't realize they would actually gain from any redistribution.

      This isn't the result of any concerted conspiracy or cartel coordination, just coincidence that made everyone convenient conscripts, including the culture goggles.

    39. Re:Well, then by Anonymous Coward · · Score: 0

      external USB drive I had you buy and told you that you had to have it plugged in while you were at home?

      Which in the context of ransomware is precisely the wrong advice - you need *offline* backups to recover, since the malware will happily encrypt any and all drives it can find. Backup to one or more external hard drives yes, but don't leave it/them connected routinely.

    40. Re:Well, then by Anonymous Coward · · Score: 0

      Exactly! I can reformat and restore completely in 2 hours or less. Or I can be running my backup desktop system (its stored in the closet) in 5 minutes and reformat and restore the other system at my leisure. Even if my several local backups should be compromised, I have an off-site backup at a trusted location available in less than half an hour.

    41. Re: Well, then by Anonymous Coward · · Score: 0

      That isn't the point.
      Said meatshield might think he's doing a real service by connecting to your computer and running the commands he was shown. So in that case it's best to waste his time so he can't scam others. In the best case you can get him to quit making the meat shield a little less meaty.

    42. Re:Well, then by Anonymous Coward · · Score: 0

      I think you analysis sucks. The so-called middle class knows they are wealthier than the so-called "poor" and they know there are people that are "rich". They aspire to be rich (or at least their children) and fear being poor.

      When they are more optimistic, they have written off their fears and if presented with an option that risks their aspirations (e.g. tax the rich) they oppose it. Conversely, when they are more pessimistic and written off their aspirations, they don't mind the tax-the-rich type of options.

      Historically, the middle class in the US has been pretty optimistic, if not for themselves, but at least the future, but there are times when that has turned. The problem we are seeing today is that in fact the middle class is shrinking (some are becoming rich, some are slipping to become poor).

      The ones slipping are certainly aware they are slipping (a situation that has befallen many people I know), but are still hoping for the future and haven't yet turned pessimistic yet. They aren't overlooking they would likely be recipients, but they resent the idea (perhaps just subconsciously) of being recipients because that would be admitting defeat and that they are actually poor. It think that explains thing much better than your analysis at least among the people I know in that situation.

    43. Re:Well, then by Ol+Olsoc · · Score: 1

      external USB drive I had you buy and told you that you had to have it plugged in while you were at home?

      Which in the context of ransomware is precisely the wrong advice - you need *offline* backups to recover, since the malware will happily encrypt any and all drives it can find. Backup to one or more external hard drives yes, but don't leave it/them connected routinely.

      No, I probably should have explained more - it was her work laptop, so the only part of it being used at home was the backing up.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    44. Re:Well, then by dbIII · · Score: 1

      Slashdot is not "getting out more".
      I'm serious. Go talk to someone that actually reads more than one book a year instead of a ranting nincompoop.
      It's a big world out there.

    45. Re: Well, then by Anonymous Coward · · Score: 0

      2 people have to pay up then you _may_ be unlocked. Read TFA.

    46. Re:Well, then by bluefoxlucid · · Score: 1

      People who read more than one book a year fall into two classes: people reading Hillary Clinton/Mike Savage and their ilk, or people reading lots of fantasy and scifi novels. The former are going to rant and rave about the rich taking all the fucking money or the poor being too lazy to get off welfare; the latter might do that, too, or they might have a lesser opinion.

      Among the more moderates, I've found that people insist that giving free money without a beating stick attached will result in everyone in America deciding a 200sqft apartment and seriously-restrictive meal budget is a fine life, and they will all live like cattle locked in a CAFO rather than going out to seek work. They don't spit and rave as much, but they still believe that either the poor are inherently lazy, or that the rich need their money taken away. That's in real life, since not many moderates comment online.

      In real life, though, I have a bad reaction to cortisoids (prednizone is... I'm not allowed near prednizone anymore); dealing with idiots is hard, and I have to keep my stress responses under control or else I'll happily just remove these morons from society. Fortunately, I've started learning to dissociate and then disrupt the anger response; and impulse control has always leaned heavily toward response-inhibition for me, and poorly toward self-activation. I've yet to get in a fist fight or cut someone's throat for being dangerously stupid.

    47. Re:Well, then by Agripa · · Score: 1

      I asked him if he thought the FBI really took payments, and if so, that they would take them by Western Union or iTunes cards or whatever.

      The DEA and other law enforcement agencies take payments. Why wouldn't the FBI?

    48. Re:Well, then by JustAnotherOldGuy · · Score: 1

      The DEA and other law enforcement agencies take payments. Why wouldn't the FBI?

      They just don't, unless they're in the form of bribes.

      --
      Just cruising through this digital world at 33 1/3 rpm...
    49. Re:Well, then by dbIII · · Score: 1

      people reading Hillary Clinton/Mike Savage and their ilk, or people reading lots of fantasy and scifi novels

      Well fuck you too if you are going to insult everyone reading scientific/technical/medical texts.

    50. Re:Well, then by bluefoxlucid · · Score: 1

      You're the one who decided "reading books" makes you a valid person. The fact that someone reads books--even technical books--means about as much as if they play video games or watch TV. At one point, books were even considered harmful to the mind, for the same reasons as TV, video games, and social media.

      The world is filled with idiots who talk about how intelligent they are because they read. It's full of people who read and don't think; and it's full of people who read and filter that information to strengthen their world-view while somehow ignoring anything contrary to that view. That, in itself, is somewhat understandable: those of us who are intelligent have to figure a way to reject anti-vaxxer bullshit and faith healing while accepting medical science, which requires using our prior experience to help shape our interpretation of information; it's difficult to identify the precise defect which causes anti-vaxxers and faith healers to reject contradictory evidence while the rest of us can identify flaws in contradictory evidence without making shit up to make ourselves feel good--or maybe we can't.

      Even then, largely well-educated, well-read, well-traveled people develop strong opinions, or simply don't care. Their opinions are often based on manipulations of fact to fit defective world views. There's a difference between well-read and intelligent; and there's a difference between intelligent and right.

    51. Re:Well, then by dbIII · · Score: 1

      You're the one who decided "reading books" makes you a valid person.

      It was a response to some pretty annoying and naive pidgeonholing you had perpetrated above.
      Lucid? I don't fucking think so.

    52. Re:Well, then by Agripa · · Score: 1

      The DEA and other law enforcement agencies take payments. Why wouldn't the FBI?

      They just don't, unless they're in the form of bribes.

      Sure they take payments; they just call them civil forfeitures.

    53. Re:Well, then by JustAnotherOldGuy · · Score: 1

      Sure they take payments; they just call them civil forfeitures.

      I agree, but as I said originally, they don't take payment in the form of ITunes gift cards or Western Union payments.

      Civil forfeitures are a crime in and of itself in my opinion, but that's just lil' ol' me.

      --
      Just cruising through this digital world at 33 1/3 rpm...
  2. I would restore by Anonymous Coward · · Score: 0

    In the unlikely event this actually would happen, then I would restore.

    My backups are secure. So I would restore from a backup. That wasn't too hard was it?

    1. Re:I would restore by Anonymous Coward · · Score: 0

      Me too, but there are a lot of idiots who don't keep backups.

    2. Re:I would restore by Anonymous Coward · · Score: 0

      I did not know you keep a backup of you, in case you contract a virus you can kill yourself and instantly restore your other copy.

    3. Re:I would restore by Wycliffe · · Score: 4, Insightful

      In the unlikely event this actually would happen, then I would restore.

      My backups are secure. So I would restore from a backup. That wasn't too hard was it?

      Backups work great for random acts of god but not necessarily for ransomware. It would be fairly trivial to create ransomware that slept a random amount of time before encrypting your files or even worse encrypt your files and then continue to function like normal for several weeks before alerting you. By that time, all your backups are also infected and even if you have a really old backup you won't have any of the recent stuff from that last several weeks or months since the initial infection. For all the people on here that are bragging about backups, even if you catch it the same day and restore it is still a huge pain and chances are if written properly it could easily be written in a way that the backups are also infected.

    4. Re:I would restore by bluefoxlucid · · Score: 1

      I don't understand. Your versioning file system can also be infected the same day?

    5. Re:I would restore by Ol+Olsoc · · Score: 1

      Backups work great for random acts of god but not necessarily for ransomware. It would be fairly trivial to create ransomware that slept a random amount of time before encrypting your files or even worse encrypt your files and then continue to function like normal for several weeks before alerting you. By that time, all your backups are also infected and even if you have a really old backup you won't have any of the recent stuff from that last several weeks or months since the initial infection. For all the people on here that are bragging about backups, even if you catch it the same day and restore it is still a huge pain and chances are if written properly it could easily be written in a way that the backups are also infected.

      Of course its a pain, and no system is foolproof. My own personal backup system doesn't have offsite storage in a fireproof container inside a guarded vault. But there is that old saying about how perfection is the biggest enemy of good enough, which is the road you are on.

      And since probably 80 percent of users have no backup at all, there is a lot of low hanging fruit before the bad guys get to multiple file backups and multiple image users.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    6. Re:I would restore by dbIII · · Score: 1

      encrypt your files and then continue to function like normal

      It would be kind of a massive giveaway when your files don't fit on the backup because so much has changed at once. Just doing a daily tar of everything is impractical in most cases so nearly every non-trivial backup system does incremental backups.

    7. Re:I would restore by Anonymous Coward · · Score: 0

      Crypto lockers will intentionally delete the old versions of files where possible. also what does your versioning file system do if you run out of disk space? If the answer is delete old versions to recover space you are also screwed. Remember a cryptolocker produces a 100% change rate, so this will typically cause snapshots to fall off anyway.

    8. Re:I would restore by Wycliffe · · Score: 1

      My own personal backup system doesn't have offsite storage in a fireproof container inside a guarded vault.

      And since probably 80 percent of users have no backup at all, there is a lot of low hanging fruit before the bad guys get to multiple file backups and multiple image users.

      It's not about the quality of the backup. It's that in order to effectively propagate a virus needs to lay low for a while so that it can get to multiple systems. If it immediately bricks your system then it can't propagate. This means that by the time it announces to you that you are infected that you have likely been infected for quite a while so all your backups are also infected. If you're lucky and your backup files aren't already encrypted then it might be possible to clean the backup before you restore it but that's assuming a person even knows enough about the virus to know where it is hiding to be able to remove it from the backup before restoring.

    9. Re:I would restore by tattood · · Score: 1

      It's that in order to effectively propagate a virus needs to lay low for a while so that it can get to multiple systems. If it immediately bricks your system then it can't propagate.

      Great, now you've told the crypto malware guys how to really screw us. Thanks a lot, jerk!

      --
      WTB [sig], PST!!!
    10. Re:I would restore by Anonymous Coward · · Score: 0

      In theory yes, in practice not so much. First off, it's really hard to get ransomware running in the first place. Granted I'm a pro, but the last time I had a virus on any system of my own, it was SCA on my Amiga ("You're computer is ALIVE!" Good times in the old days.) None since then. Second, there is not a lot to infect in the backups since they are data only. I backup data, not vendor software. Third, backups rotate. There are many copies and most of are offline. Plus, they are encrypted themselves, and only mounted during the actual backup window. So the malware needs to be really smart to catch that window, and then it has to be smart enough to catch the verify cycle.

      So yeah, in theory. But not really.

    11. Re:I would restore by lpq · · Score: 1

      If the file is encrypted "data", you can restore it to yesterday. If it is binary executable, restoring it to a few months ago shouldn't be that painful. Then you checksum the executables, add in updates, and you're good to go.

      For the virus to be effective it has to be executed at some point. So you restore those to last known safe date. The data, which isn't executed isn't going to be re-sourcing the virus any time soon.

      Backups aren't an indivisible thing unless you are using MS's image backups -- which is why I only keep programs on my MS machines and keep the data on a separate linux machine. Sure, it's a pain to reinstall Win, but its certainly doable while saving your data.

    12. Re:I would restore by Wycliffe · · Score: 1

      There are many copies and most of are offline.

      Plus, they are encrypted themselves, and only mounted during the actual backup window.

      So the malware needs to be really smart to catch that window, and then it has to be smart enough to catch the verify cycle.

      Again, none of this matters. A virus doesn't need to know anything about your backups, your backup windows, your encryption or even whether the backups even exist to infect them. In order for a virus to be effective it has to lay low for a while so that it has time to propagate. It's the reason that ebola is not really a huge issue. It kills too fast. By the time that a virus announces to you that you are infected then likely all your backups are also infected. It just has to wait a few weeks for you to back up your system like normal. Now once you discover that the virus is there, the backups are static copies so if you're lucky they aren't encrypted yet but in order to prevent them from getting encrypted you have to locate all copies of the virus on the backup and remove them before you restore. If it's an older well known virus and you can identify it then you might get lucky and find a tool that can clean your backup. The other option would require a person to dissect the backup and figure out where the virus is hiding which is beyond the skillset of most users.

  3. Easy by Alumoi · · Score: 3, Insightful

    Wipe and restore from backup. Nex!

    1. Re:Easy by 91degrees · · Score: 3, Insightful

      If people backed up, that would be a good suggestion...

      Seriously, they can probably weather the loss from the few people who are genuinely aware that you need to back this stuff up.

    2. Re:Easy by countach · · Score: 2

      I wonder if this might encrypt your backup while it's online though.

    3. Re:Easy by gravewax · · Score: 1

      someone stupid enough to be done by ransomware is unlikely to also be savvy enough to have a proper backup regime

    4. Re:Easy by Anonymous Coward · · Score: 1

      When we got hit, the infected machine also encrypted anything it could find on network shares. Our backup server didn't have any shares, so it was fine.

    5. Re:Easy by Anonymous Coward · · Score: 0

      My backup has zfs snapshots (which are readonly). I'd go "meh", and revert to a perfectly good snapshot.

    6. Re:Easy by JaredOfEuropa · · Score: 1

      Unless your nightly backup process replaced the backups of all your files with the encrypted versions.

      --
      If construction was anything like programming, an incorrectly fitted lock would bring down the entire building...
    7. Re:Easy by MrKaos · · Score: 1

      But since they don't, take their money anyway and tell them you couldn't recover their files. Only then are they ready to do backups.

      --
      My ism, it's full of beliefs.
    8. Re:Easy by MrKaos · · Score: 1

      Unless your nightly backup process replaced the backups of all your files with the encrypted versions.

      What if it replaced all you files with an mp3 of "Careless whisper" then reported you to the RIAA?

      --
      My ism, it's full of beliefs.
    9. Re:Easy by Anonymous Coward · · Score: 0

      If they replace all there backup files nightly then it really isn't a backup process. more an emergency disaster recovery for a single day. backup that only goes back a day is relatively useless beyond DR.

    10. Re:Easy by geekmux · · Score: 1

      Wipe and restore from backup. Nex!

      First Assumption - Consumers actually put forth effort to run backups.

      Second Assumption - Ransomware doesn't seek out and destroy backups.

    11. Re:Easy by Anonymous Coward · · Score: 0

      I kept telling an old friend of mine to have backups of all important files because computers can get infected with malware or break down at any time. He laughed at me, but then after almost a year of telling him this repeatedly, his HDD broke down and he lost everything he had on it. He's still not doing any backups despite the fact that even his new replacement HDD is making strange rattling sounds and making the computer hang all the time.

      Stupid people don't learn from their mistakes.

    12. Re:Easy by Wycliffe · · Score: 1

      Wipe and restore from backup. Nex!

      That's still a pain for a single day but any properly written ransomware could easily stay dormant long enough to either infect all your backups or make them old enough to be mostly worthless.

    13. Re: Easy by Anonymous Coward · · Score: 0

      File system snapshots are not backups. They just improve your system's reliability by increasing redundancy at the file system level. I hope you have good backups offlin because I once lulled myself into thinking "RAID == backup" and then one day the whole system crashed beyond repair.

    14. Re:Easy by Anonymous Coward · · Score: 0

      Ayup - and then after restoring my backups, the gloves will come off and I'll invest a little time to return the favour on the perps, find and utterly destroy their systems.

    15. Re:Easy by The-Ixian · · Score: 1

      Or replaced all of your .mp4s with Adam Sandler movies and reported you to the MPAA....

      --
      My eyes reflect the stars and a smile lights up my face.
    16. Re:Easy by Ol+Olsoc · · Score: 1

      Wipe and restore from backup. Nex!

      First Assumption - Consumers actually put forth effort to run backups.

      Second Assumption - Ransomware doesn't seek out and destroy backups.

      Damn, there is no hope for anyone! Nothing can be done! We're all doomed, and the computer kids from this country are now our overlords!!

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    17. Re:Easy by ckatko · · Score: 1

      This happened to many businesses. Live backups mean live updates to files, means all virus infected files propagate to backups.

      Offline backups, FTW.

    18. Re:Easy by MrKaos · · Score: 1

      Or replaced all of your .mp4s with Adam Sandler movies and reported you to the MPAA....

      See, if that was a virus it would just be funny. Not because of Adam Sandler though.

      --
      My ism, it's full of beliefs.
    19. Re:Easy by dbIII · · Score: 1

      Unless your nightly backup process replaced the backups of all your files with the encrypted versions.

      In which case it's not actually a backup but just a copy.
      Thanks, you've provided a good example of the difference for future use.

    20. Re:Easy by dbIII · · Score: 1

      I disagree. Properly written ransomware appears to be about making a quick buck and not about existing for long enough that antivirus vendors get a chance to do something about a variant.

    21. Re:Easy by thegarbz · · Score: 2

      If people backed up, that would be a good suggestion...

      No it's the only suggestion.

      If they didn't backup then suggest it anyway then berate the idiots for their stupidity.

    22. Re: Easy by Anonymous Coward · · Score: 0

      Ah, you incorrectly concluded those snapshots weren't replicated. At no point was anything implied about raid being backup. What he DID say was his BACKUP, NOT his primary, featured zfs snapshots. PLZ2KOMPREHENDKTHX.

    23. Re:Easy by Anonymous Coward · · Score: 0

      Pull backups, don't push them. For small shops and families, I recommend sharing your home drives with a big random password and having the central server pull the home directories with a cron job. And for big enough places, redirect the home directory to a central server and do the backups of that server.

    24. Re: Easy by darkain · · Score: 1

      ZFS also has SEND / RECEIVE to mirror snapshots to other ZFS installations on another machine. So yes, ZFS Snapshots pretty much *ARE* proper backups when implemented correctly, without the need or any other utilities.

    25. Re: Easy by Anonymous Coward · · Score: 0

      Let me guess. Dell RAID array and a power outage. I have no fucking clue why we still use Dell RAID arrays at work, but I'm not in an admin role so whatever. Just seems like once every year or two something goes oops, power is suddenly lost, and the whole file server has to be restored from backups.

  4. oooooh I am scared... by Noryungi · · Score: 0

    Who is going to save me from this dangerous hack?

    What? Windows only?

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Popcorn_Time" [path_to]\popcorn_time.exe

    Oh?

    Haven't used Windows in years. Never mind, carry on...

    --
    The right to offend is far more important than the right not to be offended. (Rowan Atkinson)
    1. Re:oooooh I am scared... by Anonymous Coward · · Score: 0

      given the simplicity of the code it could be converted to run on Mac on Linux in all of a few minutes of effort. The better thing to be scared of is the morons who keep trying to convert dumbshit users to come to Linux, we don't need them to make us a more attractive target as we have nothing preventing this sort of attack either.

    2. Re:oooooh I am scared... by Anonymous Coward · · Score: 0

      Yep, I'm one malicious AUR package from disaster. Quite a few ubuntu people will be one bad PPA from it too.

      On the other hand, whenever I use Windows and find myself Googling for variously-themed and garish closed-source shareware dodgy software coded by Russian schoolchildren to do anything at all, and end up at some shady download site to get it, I take a wild guess at which "download" button is the right one, and hope for the best. It's a miracle anyone doesn't have an infection on Windows.

    3. Re:oooooh I am scared... by Maritz · · Score: 1, Insightful

      lol. Don't break an arm patting yourself on the back just because you don't use windows.

      --
      I do not want your cheap brainburning drugs. They are useless for work. And I am a working man today.
    4. Re:oooooh I am scared... by MrKaos · · Score: 1

      Who is going to save me from this dangerous hack?

      Rege Dit.

      --
      My ism, it's full of beliefs.
    5. Re:oooooh I am scared... by stealth_finger · · Score: 1

      Who is going to save me from this dangerous hack?

      Me, for a nominal fee* of course


      *payable in advance, non refundable, results not guaranteed

      --
      Wanna buy a shirt?
      https://www.redbubble.com/people/stealthfinger/shop?asc=u
    6. Re:oooooh I am scared... by Ol+Olsoc · · Score: 1

      lol. Don't break an arm patting yourself on the back just because you don't use windows.

      You have to admit, the installed user base of malware is best on Windows, those Mac Hipsters and Linux geeks are never going to catch up to you guys.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    7. Re:oooooh I am scared... by tepples · · Score: 1

      What? Windows only?

      I don't know. Currently I don't have a spare physical machine on which I'm willing to test it in Wine.

  5. cyber-terrorists by MikeMcMahon · · Score: 1

    aiding and abetting cyber-terrorists to decrypt your porn stash... gonna have a bad time :P

  6. That's awful... by Anonymous Coward · · Score: 0

    ... but genius at the same time.

  7. Fucking Muslims by Chrisq · · Score: 0, Flamebait

    ""all the money that we get goes to food, medicine, shelter to our people"

    Bombs, guns, and support of terrorism in the West more like

    1. Re:Fucking Muslims by Anonymous Coward · · Score: 0

      i was gonna say bitches, bling and a trip to Turkey

    2. Re:Fucking Muslims by Maritz · · Score: 1

      I bet it blows your mind that the people they're fighting are also muslims.

      --
      I do not want your cheap brainburning drugs. They are useless for work. And I am a working man today.
    3. Re:Fucking Muslims by Anonymous Coward · · Score: 0

      Israel must not need all that border security any more then. Someone should tell them.

    4. Re:Fucking Muslims by Kjella · · Score: 4, Informative

      I bet it blows your mind that the people they're fighting are also muslims.

      Because...?

      I was walking across a bridge one day, and I saw a man standing on the edge, about to jump. I ran over and said: "Stop. Don't do it."

      "Why shouldn't I?" he asked.

      "Well, there's so much to live for!"

      "Like what?"

      "Are you religious?"

      He said: "Yes."

      I said: "Me too. Are you Christian or Buddhist?"

      "Christian."

      "Me too. Are you Catholic or Protestant?"

      "Protestant."

      "Me too. Are you Episcopalian or Baptist?"

      "Baptist."

      "Wow. Me too. Are you Baptist Church of God or Baptist Church of the Lord?"

      "Baptist Church of God."

      "Me too. Are you original Baptist Church of God, or are you Reformed Baptist Church of God?"

      "Reformed Baptist Church of God."

      "Me too. Are you Reformed Baptist Church of God, Reformation of 1879, or Reformed Baptist Church of God, Reformation of 1915?"

      He said: "Reformed Baptist Church of God, Reformation of 1915."

      I said: "Die, heretic scum," and pushed him off.

      Religious wackos can rant and rave about people who believe in false gods or worse no gods at all, but worst of all are those who believe in a "perverted" version of their own god and those who've abandoned the faith. Not sure what your point is though, I care about how many people want to kill me, how many other people they want to kill is of lesser concern.

      --
      Live today, because you never know what tomorrow brings
    5. Re:Fucking Muslims by Anonymous Coward · · Score: 0

      quick, mod this 'plays to stereotypes, group think and my need to be morally superior'.

    6. Re:Fucking Muslims by Anonymous Coward · · Score: 0

      I do not see anything wrong with this. I too would be concerned who want to kill me based on their theological beliefs however wacked out they are.

    7. Re:Fucking Muslims by Anonymous Coward · · Score: 0

      Why the outrage? It's just the crooks topping the extortion cake with a cherry of fraud.

    8. Re:Fucking Muslims by nitehawk214 · · Score: 1

      You are the stupidest person alive if you think any money goes to help anyone other than the writers of the ransomware.

      --
      I'm a good cook. I'm a fantastic eater. - Steven Brust
    9. Re:Fucking Muslims by dave420 · · Score: 1

      And there he is - I thought you were dead or something - I've not read your mindless drivel on here in ages! I'd say "welcome back" but you're not.

    10. Re:Fucking Muslims by Anonymous Coward · · Score: 0

      Nice story, but you've kinda missed the point.

      "The people they're fighting are other Muslims" - that's not the important bit. The important bit is the corollary: almost all the people who are in the front lines fighting against ISIS are Muslims.

    11. Re:Fucking Muslims by Rakarra · · Score: 1

      Nice story, but you've kinda missed the point.

      "The people they're fighting are other Muslims" - that's not the important bit. The important bit is the corollary: almost all the people who are in the front lines fighting against ISIS are Muslims.

      They're also all humans, so we ought to kill all humans, everywhere.

    12. Re:Fucking Muslims by Anonymous Coward · · Score: 0

      Ah, a joke for white people.

    13. Re:Fucking Muslims by Anonymous Coward · · Score: 0

      those who've abandoned the faith

      What's wrong with victims of cults? Too noisy? Too timid?

  8. Starve! by Anonymous Coward · · Score: 0

    A starving man steals bread, not money. Let the thieves starve. They'll just give it to ISIS anyway.

    1. Re:Starve! by Maritz · · Score: 1, Insightful

      If you watch a film, do you have to constantly ask other people in the room what's going on? It kinda sounds like you must. To be this confused about real world stuff, I'd have thought you'd need to be about seven years old or something.

      --
      I do not want your cheap brainburning drugs. They are useless for work. And I am a working man today.
  9. Black Mirror? Is that you? by Zaatxe · · Score: 1

    Sounds like a plot for the series...

    --
    So say we all
  10. What Friends? by Anonymous Coward · · Score: 0

    The best way I've found to avoid malware is to avoid people who have malware. No friends for me. I'm malware free.

  11. I will format the harddrive by Anonymous Coward · · Score: 0

    I will format the harddrive,
    re-install the OS do my best to ensure that everything is OK,
    Install the crashplan agent,
    take the USB drive from the closet and restore my data from that,
    restore the data that I created after last USB backup from Crashplan.

  12. Kevin Bacon Ransomware by Anonymous Coward · · Score: 0

    Infect the world and everybody gets a free encryption key.

  13. Fraud + Bitcoin by Anonymous Coward · · Score: 0

    Why am I not surprised?

  14. Do not negotiate with terrorists by Anonymous Coward · · Score: 0

    > So what would you do if this ransomware infected your files?

    As far as I'm concerned, this no different than if the media where the files are stored had caught fire or was exposed to some other destructive calamity.

    For all intents and purposes your files are gone, act accordingly.

  15. And people who back up to a network share, or rota by raymorris · · Score: 1

    There are a lot of people who backup to a network share, and others who keep only one copy of backups. Most ransomware will encrypt network shares as well. People who have only one copy are hoping nothing goes wrong at night; in the morning they'll have two copies pg garbage.

    I created a backup / warm spare system based on read-only rsync pull to a remote server that keeps several de-duplicated copies, and makes each backup bootable as a VM. I called it Clonebox.

  16. The solution. by Anonymous Coward · · Score: 0

    If you have another PC laying around, back it up, infect it. reinstall, infect it. and then get the free key. lol. I wonder how they determine that you have infected two other people.

    But of course the real answer is to hunt down the bastards and slit their throats.

    1. Re:The solution. by Anonymous Coward · · Score: 0

      Reading/comprehension disorder much?
      2 other suckers have to pay in order to get your free key.

    2. Re:The solution. by Anonymous Coward · · Score: 0

      lol. I wonder how they determine that you have infected two other people.

      Lol! Your friends have to pay first, idiot! Then you get the referral discount! Malware is business now, antisocial moron.

  17. Easy solution by kaur · · Score: 2, Funny

    1) my boss
    2) my mother-in-law

    I see this as win-win-win situation.

    1. Re:Easy solution by MrKaos · · Score: 1

      1) my boss 2) my mother-in-law I see this as win-win-win situation.

      Ahhhh, so this is Step 3., before Profit!

      --
      My ism, it's full of beliefs.
    2. Re:Easy solution by Anonymous Coward · · Score: 0

      This is how your idea will play out

    3. Re:Easy solution by Anonymous Coward · · Score: 0

      Kid should use the $200 to buy a gun instead.

    4. Re:Easy solution by D00MSlayer · · Score: 1

      Step 2*

    5. Re:Easy solution by surd1618 · · Score: 1

      I think you should move up the food chain.
      And if a coworker or a relative you like gets infected, then tell them you can fix it with your tech skills, and put in the secret decryption code when they're not looking. So you'll either make $B$ or you'll be a hero.

  18. Forward to your leftist "friends" by Anonymous Coward · · Score: 0

    The claim by the perpetrators is sure to touch them. You just need two to take the bait and you might be off the hook. If the perps don't honor the deal, it's still funny.

  19. Oh Yeah, your so poor by Anonymous Coward · · Score: 0

    Oh yeah, your so poor that to make ends meet you use expensive computer equipment to develop Ransomware to then infect people in the hope they cough up some dosh. WHY don't you just sell your IT equipment instead.

    1. Re:Oh Yeah, your so poor by Bonobo_Unknown · · Score: 4, Funny

      Teach a man to phish...

      --
      We don't believe in radical loony monotheistic religions from the middle east -- we're Christians.
  20. been_here by breun · · Score: 5, Interesting
    From the article:

    Once started, the Popcorn Time ransomware will check to see if the ransomware has been run already by checking for various files such as %AppData%\been_here and %AppData%\server_step_one. If the been_here file exists, it means the computer has already been encrypted and the ransomware will terminate itself. Otherwise, it will either download various images to use as backgrounds or start the encryption process.

    So, everyone should just make sure %AppData%\been_here and %AppData%\server_step_one exist? :)

  21. What would I do? by Gaxx · · Score: 1

    Probably restore from last full backup. You do have backups, right?

    --
    -- Gaxx
    1. Re:What would I do? by tepples · · Score: 1

      So what would you do if you discover that this ransomware has been slowly infecting your backups for the past several weeks?

    2. Re:What would I do? by JustAnotherOldGuy · · Score: 1

      So what would you do if you discover that this ransomware has been slowly infecting your backups for the past several weeks?

      Then I'd go back further than several weeks.

      My backups are separate, individualized, and not of the constantly online variety. Multiple separate drives, stored offsite, etc etc etc.

      --
      Just cruising through this digital world at 33 1/3 rpm...
    3. Re:What would I do? by AvitarX · · Score: 1

      You're lucky if a few weeks isn't worth dramatically more than a Bitcoin (or perhaps unlucky).

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
    4. Re:What would I do? by JustAnotherOldGuy · · Score: 1

      You're lucky if a few weeks isn't worth dramatically more than a Bitcoin (or perhaps unlucky).

      A few weeks on my home PC wouldn't be worth shit.

      My email is all online so that's not a worry; the rest of my stuff is backed up frequently enough so it's not a big deal. And yes, I go in and spot-check a few files from time to time so if they were being bunged up I'd (probably) know about it.

      Even so, if my entire PC were to blow up or get stolen it's not like my life would come to an end. It would be a medium-sized inconvenience for a little while, but also a nice excuse to go out and buy a new one. :)

      --
      Just cruising through this digital world at 33 1/3 rpm...
  22. All part of the scam. by Gravis+Zero · · Score: 4, Insightful

    "a group of computer science students from Syria," and that "all the money that we get goes to food, medicine, shelter to our people. We are extremely sorry that we are forcing you to pay but that's the only way that we can keep living."

    This is a brilliant twist on malware. These are not people from Syria but rather a story concocted to try and have you help them. It's basically, it's an alternate version of the "Nigerian Prince" that needs money to bribe his captors to release him. Logically, a person in a warzone cannot exchange bitcoin for money or goods which makes the whole thing implausible from the start. I would bet what when they tear the binary apart, they'll find that it's been compiled for the Russian locale.

    So what would you do if this ransomware infected your files?

    A) wipe your system
    B) load Linux instead of Windows
    C) restore files from backups

    --
    Anons need not reply. Questions end with a question mark.
    1. Re:All part of the scam. by tinkerton · · Score: 1

      Of course these aren't computer students from Syria. It's remarkable that you're the only one pointing this out.

    2. Re:All part of the scam. by Anonymous Coward · · Score: 0

      Russia is almost as bad anyway..

    3. Re:All part of the scam. by Anonymous Coward · · Score: 0

      The beautiful part of Linux compromises is that the user rarely ever realizes they are infected. They'd have to be able to admit they are wrong occasionally to ever see it.

    4. Re:All part of the scam. by Anonymous Coward · · Score: 0

      Though probably correct, it must feel really good to talk with confidence and authority when you've no idea what you're talking about and no way of discerning the facts.

    5. Re:All part of the scam. by rjstegbauer · · Score: 1

      Yes, you're right. Very likely *not* from Syria, but I think there are a social justice sympathizers that will *actually* think they are doing good by paying.

      That said, this past weekend, *I* gave money to a person who walked up to me as I was getting into my car who had "car trouble". I know I was scammed, but I have the strange opinion that this was his "work"...especially since it was blustery cold out.

    6. Re:All part of the scam. by mark-t · · Score: 1

      Unless you are suggesting that Linux malware is actually just the mindset of the people that use it, detecting it would not be dependent on whether or not they admit to being wrong.

    7. Re:All part of the scam. by StormReaver · · Score: 1

      A) wipe your system
      B) load Linux instead of Windows
      C) restore files from backups

      This is what I did back in 1997 when a Windows virus wiped out my hard disk. Sadly, I was a broke college student who didn't have the money to afford backups, so I lost everything. I had to start from scratch, anyway, so I started with Linux. I had dabbled with Linux on and off since 1993, but that Windows virus was the push I needed to commit to the switch. I've never regretted it.

    8. Re:All part of the scam. by Anonymous Coward · · Score: 0

      I don't disagree, but I think the basis for your conclusion is incorrect. I'm pretty sure you can both go to work, buy stuff at the local market and sell a bitcoin when you live in Syria. Just watch out for bombs and gunshots while you do. ..but that's unimportant because we all know the russians did it!

    9. Re:All part of the scam. by bmo · · Score: 1

      Are you me? Nearly exact same scenario, except that Windows didn't need a virus to lose everything. It just needed to puke while backing up my files.

      I rage quitted Windows and never looked back.

      Best rage quit ever.

      --
      BMO

    10. Re:All part of the scam. by retchdog · · Score: 1

      Linux malware is actually just the mindset of the people that use it

      Just ask a random user what they think of systemd.

      --
      "They were pure niggers." – Noam Chomsky
  23. "Friends" by dohzer · · Score: 1

    Do they mean "friends" or people I have in my address book. There's a difference; a very distinct one.

    1. Re:"Friends" by Anonymous Coward · · Score: 0

      if you are willing to purposefully infect their computer with ransom ware they cant be your friend.

    2. Re:"Friends" by Anonymous Coward · · Score: 0

      I don't think it matters. You'll be charged with extortion and computer terrorism, and you'll spend some time in federal "pound me in the ass" prison. You won't have any friends when you get out, and the terms of your parole will say that you're not allowed to use a computer.

    3. Re:"Friends" by ArsenneLupin · · Score: 1

      Indeed. In that case, they are a "friend" rather than a friend...

  24. Sorry?? by Anonymous Coward · · Score: 0

    " We are extremely sorry that we are forcing you to pay but that's the only way that we can keep living." - I did interrogate a murderer once who used this excuse for killing his victims after a robbery. I'm sure that made everyone fell just as warm and fuzzy as it did for that sociopath...

  25. 1) Install two VMs ... by Anonymous Coward · · Score: 0

    2) Infect VMs 3)??? 4) Cha ching?

    1. Re:1) Install two VMs ... by Anonymous Coward · · Score: 0

      3). RTFA properly, because the 2 VMs won't pay

  26. Safer To Be Infected? by Anonymous Coward · · Score: 0

    I think some of the political parties could use some help with encryption.

  27. Trolling for Trolls by xtsigs · · Score: 1

    Perhaps I can catch me some trolls. All I have to do is snooker them into going to the link and installing the ransomware on their machine. I'll just call it "a personal message from Putin on how you can help make Russia Great Again."

  28. why not nukes??? by Anonymous Coward · · Score: 0

    so this is how united stated is doing to take all middle east money? with a prank?

  29. Why are you using a computer by Anonymous Coward · · Score: 0

    You care about the files on the net?

  30. Can we call this the Amway virus? by Anonymous Coward · · Score: 1

    Seriously... it's like Amway. Or maybe it's the Herbalife virus.

  31. It's on Windows by hcs_$reboot · · Score: 1

    Why isn't it mentioned anywhere the ransomware works on Windows and only on Windows? Is it to avoid another Windows-bashing? Or is it that obvious?

    --
    Slashdot, fix the reply notifications... You won't get away with it...
    1. Re:It's on Windows by Ol+Olsoc · · Score: 1

      Why isn't it mentioned anywhere the ransomware works on Windows and only on Windows? Is it to avoid another Windows-bashing? Or is it that obvious?

      It has been pointed out. Then the Windows apologists start screaming about how it can be made to work on OSX and Linux.

      Which isn't the point, because its a Windows thing.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    2. Re:It's on Windows by tepples · · Score: 1

      Because there's probably no positive or negative result entry in Wine AppDB.

  32. i would just say by FudRucker · · Score: 1

    FOAD to the dirty crooks, break out the live USB Linux distro of gparted, wipe the drive with --sgdisk-zap-all /dev/sda then put in a new filesystem, reinstall my favorite flavor or Linux, and be glad i keep all my personal stuff on another USB thumbdrive

    --
    Politics is Treachery, Religion is Brainwashing
  33. Popcorn Time? by oshkrozz · · Score: 2

    Based on the title I think we know exactly who is behind this Malware don't have to look farther then MPAA for the funding of this program.

  34. If I was American by aliquis · · Score: 1

    Ask my government to nuke all Muslims.

    But now I'm Swede so I'm not allowed to and we don't have any nukes anyway :D

  35. What would I do? by slashdice · · Score: 1

    If I ever met them, I WOULD KICK THEIR ASS. Lameness filter encountered. Post aborted! Filter error: Don't use so many caps. It's like YELLING.

    --
    Copyright (c) 1990 - 2014 Dice. All rights reserved. Use of this comment is subject to certain Terms and Conditions.
  36. Hey Guys, by Oswald+McWeany · · Score: 1

    Hey guys, any of you want to try out this fantastic new software I've just got, let me give you a link, you can download it for free.

    --
    "That's the way to do it" - Punch
  37. When did popcorn time become malware? by Anonymous Coward · · Score: 1

    I must have been napping. When did popcorn time change from a pirate movie operation to a malware site. Early this year I was shocked when I found the long time legitimate Vuze bit torrent client switched to a malware model. (they infect your browser so adds pop up and redirects your pages to yahoo sites-- they admit they did this on their blog as a revenue measure as though that makes it legit.)

    Also when did Ozzy become and actor?

    1. Re:When did popcorn time become malware? by MayeulC · · Score: 2

      Popcorn time was an open source experiment, and was completely shut down (afaik) following some legal threats. Naturally, and predictably, this spun off countless forks of various quality and with varying ethical standards.

      The name is probably just a clickbait to trick more users into installing the malware.

      IMHO the movie industry should have embraced the popcorn time distribution model, maybe with some encryption, and make the content paid-for/ads-subsidized (that's just an example, there are countless of other ways to monetize such a product, some of which are better than others). Use the brand/Name recognition to bootstrap the next-gen movie content distribution platform (think steam). Sign me up!

  38. Hosts files work vs. this threat... apk by Anonymous Coward · · Score: 0

    See subject - By stalling it's network communication as follows:

    0.0.0.0 3hnuhydu4pd247qb.onion
    0.0.0.0 popcorn-time-free.net

    * Using those entries in your custom hosts file to block communication with them...

    (SOURCE = https://www.bleepingcomputer.c... )

    APK

    P.S.=> For more protection + more speed & anonymity online via hosts files, see APK Hosts File Engine 9.0++ SR-4 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/ ... apk

    1. Re:Hosts files work vs. this threat... apk by Anonymous Coward · · Score: 0

      oh dear fuck.... not more of this shit. Blacklisting whackamole is not a solution. It's a bandaid at best.

    2. Re:Hosts files work vs. this threat... apk by BronsCon · · Score: 1

      Host files only work if you're the original victim; if your friend gets infected, opts to go the "free" route, and sends you the binary directly (because you tell him the site won't load for you) you're still stuck. Even worse, you might be more screwed if the ransomware no cannot call home to verify payment after you do pay up.

      Hosts files aren't a universal fix, bro. Sometimes you just need to keep offline backups.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
  39. Hosts files work vs. this threat... apk by Anonymous Coward · · Score: 0

    See subject - By stalling it's network communication as follows:

    0.0.0.0 3hnuhydu4pd247qb.onion
    0.0.0.0 popcorn-time-free.net

    * Using those entries in your custom hosts file to block communication with them...

    (SOURCE = https://www.bleepingcomputer.c... )

    APK

    P.S.=> For more protection, speed & anonymity online via hosts files, see APK Hosts File Engine 9.0++ SR-4 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/ ... apk

  40. Reformation of 1879 by MightyDrunken · · Score: 2

    Shows you what scum the Reformed Baptist Church of God, Reformation of 1879 are.

  41. Hosts files work vs. this threat... apk by Anonymous Coward · · Score: 0

    See subject - By stalling it's network communication as follows:

    0.0.0.0 3hnuhydu4pd247qb.onion
    0.0.0.0 popcorn-time-free.net

    * Using those entries in your custom hosts file to block communication with them...

    (SOURCE = https://www.bleepingcomputer.c... )

    APK

    P.S.=> For more protection, speed & anonymity online via hosts files vs. this & other online threats, see APK Hosts File Engine 9.0++ SR-4 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/ ... apk

  42. What would I do by teknosapien · · Score: 1

    Since I do backups nightly on all home machines - format reinstall

    --
    no matter how good it is, it is human nature always wants to make things better
  43. Funny it works here though, eh? by Anonymous Coward · · Score: 0

    It works here just fine to block this threat & you know it - end of subject/period.

    APK

    P.S.=> You little unidentifiable anonymous posting fools keep making me look GOOD - thanks! apk

  44. Would this work without crypto-currency? by Ambassador+Kosh · · Score: 1

    I have wondered about this for a while. These groups can't use cash due to it being easy to track in the mail and needing to receive the cash, They also can't do credit cards since that could be traced almost immediately and the account seized.

    Does ransomware work on the scale it exists today or larger without crypto-currency? Right now I can't think of any way to have it work on a large scale without crypto-currency.

    If ransomware really can't work without crypto-currency then this would have to be factored in as part of the cost of crypto-currency and it should be seriously looked at to decide if the costs are worth the benefits of the currency. I know we could not truly get rid of crypto-currency but if western countries did not allow any financial institutions to convert to or from crypto-currency and companies where banned from accepting it or paying that would effectively kill the currency.

    Of course if ransomware could work fine without crypto-currency a different course of action is needed. I just see a systemic flaw right now that allows ransomware and attacking users is not going to fix the issue. Like all large scale issues if the flaw is systemic it must be fixed at the system level not at the user level. OS mitigation strategies should be seriously looked at also. Any application that tries to change large numbers of user files should be stopped quite quickly for suspicious activity.

    --
    Computer modeling for biotech drug manufacturing is HARD! :)
    1. Re:Would this work without crypto-currency? by Anonymous Coward · · Score: 0

      Ransomware cannot exist without cryptocurrency. It was tried a few times and ended with the perps being made an example of. But now they can make their finances too difficult to trace and transactions too difficult to reverse.

      I really really wish the bitcoin miners would agree to use time unwinding erasure to smash the ransomware guys.

    2. Re:Would this work without crypto-currency? by Agripa · · Score: 1

      If ransomware really can't work without crypto-currency then this would have to be factored in as part of the cost of crypto-currency and it should be seriously looked at to decide if the costs are worth the benefits of the currency.

      Then also factor in the benefits of using crypto-currency instead of cash which the law enforcement can seize on bogus charges at any time without charging you with anything.

    3. Re:Would this work without crypto-currency? by Ambassador+Kosh · · Score: 1

      I absolutely agree with the benefits of crypto-currency. I just think we should seriously look at all the costs and benefits of crypto-currency and see if we can modify them to keep the benefits and cut back on the costs or if we should have them at all or if we should do noting at all.

      --
      Computer modeling for biotech drug manufacturing is HARD! :)
  45. What would I do? by JustAnotherOldGuy · · Score: 1

    "So what would you do if this ransomware infected your files?"

    I'd restore from backups.

    --
    Just cruising through this digital world at 33 1/3 rpm...
  46. Great... by trollebolle · · Score: 1

    Now ransomware has gained a new delightful social aspect

  47. Two treats in one ... by BenBoy · · Score: 1

    Appears we're looking at the unholy spawn of ransom-ware and multi-level-marketing. Fetch holy water and an axe.

  48. Seems familiar... by Translation+Error · · Score: 1

    It sounds like someone has watched Ringu too many times.

    --
    When someone says, "Any fool can see ..." they're usually exactly right.
  49. With friends like those... by Anonymous Coward · · Score: 0

    With friends like those, who needs Putin?

  50. Pyramid scheme? by onemorechip · · Score: 4, Funny

    Sounds a lot like a pyramid scheme -- this could be illegal.

    --
    But, I wanted socialized health insurance!
  51. If original victim's safe? by Anonymous Coward · · Score: 0

    See subject: You said it - how would he send it if he can't get it? Can't be hurt by what you can't touch in the 1st place - hosts do that for you per the blocking entries I noted (& even IF you were already infested? This malicious threat can't "talk back to mama" in its C&C network either - double bonus!) - you can't even BECOME the "original victim" by blocking this thing out in the 1st place!

    (... & "there ya go" - but I am totally for your backups solution (do it myself daily))

    As far as email/spam/phish payloads (were it done thus)? Malicious links/hosts-domains get blocked by there hosts too (junkmail, in THIS capacity, is EXTREMELY useful to me regarding hosts).

    APK

    P.S.=> Lastly - w/ "friends" like that? Who needs enemies, lol - pick BETTER 'friends' man... apk

    1. Re:If original victim's safe? by BronsCon · · Score: 1

      How does the hosts file protect you before the threat has been discovered and its host and C&C domains have been added to the hosts file? There will always be a patient zero; and this encrypts regardless of whether it can talk to the C&C server, so you're double screwed if it can't phone home.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
  52. Ess Pee Aitch by Anonymous Coward · · Score: 0

    You know in your heart it's what's required

  53. Prove me validly technically wrong instead by Anonymous Coward · · Score: 0

    See subject & you can't manage that here https://it.slashdot.org/comments.pl?sid=9982895&cid=53468617/ can you? Obviously not, lol!

    * You know that's what's REALLY required from unidentifiable anonymous trolls such as yourself but it's IMPOSSIBLE for your inferior brains to manage, lmao!

    APK

    P.S.=> Thanks for making ME look GOOD, & those of "your kind" (mere "ne'er-do-well" do-nothings) look, well - rotflamo "not so good" by comparison to myself... apk

  54. I didnt read your post... by Anonymous Coward · · Score: 0

    ...I never do. But I do get warm fuzzies inside knowing that you have internalised SPH and understand why its necessary. If only you would *act* on this understanding, your immediate circle would be so grateful. You could give up this OC /. behavior. Hell, you might even make enough of a recovery to start creating useful software - wouldn't that be a wonderful new achievement?

  55. "Rinse, Lather & Repeat" unidentifiable troll by Anonymous Coward · · Score: 0

    See subject & prove me validly technically wrong in my original post as you're challenged to + FAIL in https://it.slashdot.org/comments.pl?sid=9982895&cid=53470817/

    * Once again, thanks for making ME look GOOD & yourself like the effete unidentifiable cowardly + apparently illiterate STOOGE you clearly are, lol!

    APK

    P.S.=> I get the "warm fuzzies" looking @ you wasting your time apparently suffering delusions of grandeur on your part thinking you're a psychiatric pro as you attempt to libel me... apk

  56. Re:And people who back up to a network share, or r by anybody_out_there · · Score: 1

    I created a backup / warm spare system based on read-only rsync pull to a remote server that keeps several de-duplicated copies, and makes each backup bootable as a VM. I called it Clonebox.

    Do you have a HOWTO or similar? I want to set up something like this with a new server (best practices from the start, so I hope)

  57. Can't release it right now, company sells for $25 by raymorris · · Score: 1

    Right now I can't release the documentation because the company I used to work for sells it, with off-site backups to their cloud. If you remind me a month from now, I may be able to release something.

  58. Restore from offline backup. by Anonymous Coward · · Score: 0

    Done and done.

  59. Use your Bitcoins wisely by Anonymous Coward · · Score: 0

    I think it would be a much better solution to pool your resources with others being affected by this extortion and use those bitcoins to hire an assassin to make sure these people no longer have to worry about committing crimes to live.

  60. Game theory by Anonymous Coward · · Score: 0

    ... get their files back ...

    It's easy to include code that installs registry keys or configuration files on a computer, keeping the malware alive: Recovering the damaged files from a backup isn't enough. There's also removing the malware and the source of (recurring) infection. How many non-tech people backup personal data? How many can install Windows and configure it to their preferred settings? In my social circle that count is zero and that is why this sort of extortion keeps appearing. As a worst case scenario, 2^(n)-1 people will have carried the infection to 2^n people who will have to pay the ransom or lose their digital history (making a total infected population of 2^(n+1)-1 people).

    ... infect two other people and have them pay the ransom ...

    Presumably, the pyramid scheme portion of the reward means if all your friends have already infected one another, you've lost your data. Reward the criminals and externalize your problems onto the people closest to you: How many people will act like a drug addict to keep their digital history safe? It's both an ethical dilemma and an exercise in game theory. The game questions include 'What if your friends discover your crime?' 'What if your friends then attempt to infect you (possibly revealing you as the source of the infection)?', 'Can the carriers hide the fact they didn't pay the ransom?', 'Will the malware admit your friend enabled the infection?'.

  61. What I would do if infected by divide+overflow · · Score: 1

    So what would you do if this ransomware infected your files

    Simple: I'd restore from my backups. Don't have backups? Then you are a fool.

  62. Needs Examples by Anonymous Coward · · Score: 0

    The USS proposal (similar to UBI) could really benefit from several examples showing various families. Not the generic "a family in 10% blah blah" but "Joe and Jane earning a combined $127,000/hr could see X." Or better yet, an online calculator that lets people plug in their own numbers.

  63. Theoretical bs, not the case here... apk by Anonymous Coward · · Score: 0

    See subject: It works here, bottom-line & since you ask? My sources in my program (10 of em) & 5 more I use that update even more frequently are pretty "ontop of their game" that way (they find them fast) + another 13 security sites (e.g. ESET, palo alto networks, CISCO, F-secure, bleeping computer, secureworks, gary warner's blog, fireeye, shadowserver & securelist) do the rest, quickly!

    Plus, DNS' 24 propogation lag + odds (of not hitting the malicious spots) works in my favor as well (as it does anyone else).

    APK

    P.S.=> Nothing's perfect & nothing does it all - BUT, hosts do FAR more for FAR less vs. other "so-called 'solutions'" that are riddled w/ security issues + inefficiency (locally installed DNS/antivirus) OR don't work fully ("AlmostALLAdsBlocked") by default, deceitfully no longer doing the job they're intended to do... apk

  64. Do they have to be friends? by snizzitch · · Score: 1

    Or could I include an enemy or two as well? Can the "friends" include VMs of which I just took a rollback snapshot a few moments ago?

  65. What I would do is ... by Anonymous Coward · · Score: 0

    I would kill the power from the cable and give the system a "hard bounce" if I saw something like that.
    I would then take the drive and slave it in a box running a very different kind of OS.
    If you are lucky the hard bounce kept the encryption attempt from being able to take hold from a graceful restart.
    At that point you should be able to get the files you need off the drive.
    Format. Reinstall, restore , or whatever your back-up solution is.

  66. So what would you do? by Anonymous Coward · · Score: 0

    "So what would you do if this ransomware infected your files?"

    I would dance around, post on Facebook and make a selfie post about stupid computer not working.

    If none of that helped, I would press the on/off button until it falls off and buy a new windows computer. /s

  67. Just use Dropbox or similar by Anonymous Coward · · Score: 0

    It has been like three or four years now since I made the switch to keeping all my important stuff in the cloud (mostly Dropbox). That, combined with all my games being on Steam/GOG, means that if my computer/hard-drive suddenly dies, I don't lose anything. Same if my phone gets stolen.

  68. Hey Muslims are just like us by Anonymous Coward · · Score: 0

    hey Muslims are just like us, enjoying parties and so on.

  69. Delete and roll back to a safe backup? by Anonymous Coward · · Score: 0

    Is there any other option?

  70. Superior Hosts File = required for this issue by Anonymous Coward · · Score: 0

    See subject & this link PROVING hosts solve this issue https://it.slashdot.org/comments.pl?sid=9982895&cid=53468617/ which you can't prove wrong.

    * Superior Hosts File works here = Ess Pee Aitch/SPH, lol!

    APK

    P.S.=> Thanks for trolling me by unidentifiable anonymous posts (which you're reduced to as you can't validly technically prove me wrong & hosts work here) proving me YOUR SUPERIOR, again as always - lol!... apk

  71. Chmeee's Solution by Agripa · · Score: 1

    So what would you do if this ransomware infected your files?

    I would find considerable pleasure in hunting down the instigator.

  72. Ess Pee Aitch by Anonymous Coward · · Score: 0

    I didnt read your post.

    Do you disagree that continuously bookmarking all these comments and obsessively responding is symptomatic of a mental health issue? You should ask that same question of a health professional. I'm responding as a genuine effort to get you to seek the help you need. Why are you responding exactly?

  73. Heh by Anonymous Coward · · Score: 0

    Here comes two quick VM's, "proof of infection", and 2 very deleted VM's after the fact.

    Next.

  74. What happened?! by Anonymous Coward · · Score: 0

    You didn't reply to my last response. I'd love to believe it's because you finally did SPH!

  75. Superior Hosts File works here by Anonymous Coward · · Score: 0

    I defend myself via facts you can't prove wrong (hosts work here) https://it.slashdot.org/comments.pl?sid=9982895&cid=53468617/ you unidentifiable anonynmous "ne'er-do-well" that projects his own mental issues onto others.

    APK

    P.S.=> Hosts work vs. this threat & that's that... apk

    1. Re:Superior Hosts File works here by Anonymous Coward · · Score: 0

      So you don't disagree? Seriously, go ask that question of a professional

  76. Superior Hosts Files work vs. this threat by Anonymous Coward · · Score: 0

    See subject & you can't disprove hosts work vs. this threat https://it.slashdot.org/comments.pl?sid=9982895&cid=53468617/ unidentifiable ac "ne'er-do-well" cowardly troll that you are. You lose as always. It's just what you do!

    APK

    P.S.=> Grow up loon... apk

  77. Ess Pee Aitch by Anonymous Coward · · Score: 0

    Surprisingly slow in your "response" - your OC obligations getting to be a bit of a strain? It's another reason why you need to SPH. Maybe once you've overcome your illness you will at last be able to fulfill your ambition of creating code that actually works well - wouldn't that be satisfying?

  78. I don't disagree host worked here by Anonymous Coward · · Score: 0

    See subject & this article's topic + how Superior Hosts Files stop it https://it.slashdot.org/comments.pl?sid=9982895&cid=53468617, you imbecilic little troll.

    * Argue w/ the facts in that link I just posted & by the way: YOU'RE NO PSYCHIATRIC PRO "Dr. Quack 'SiDeWaLk-ShRiNk of /." (laboring under your own "delusions of grandeur", lol) - you fail!

    APK

    P.S.=> Badly - yes, LOL, I am LAUGHING @ YOU as usual... apk

  79. Great xmas gift idea by Anonymous Coward · · Score: 0

    Maybe ask santa for some funds to help you SPH?

    1. Re:Great xmas gift idea by Anonymous Coward · · Score: 0

      See subject & this link's undeniable truth (you LOSE, loser - grow up & get on topic) https://it.slashdot.org/comments.pl?sid=9982895&cid=53507817/

      APK

  80. Aw, can't win? LOL, you LOSE by Anonymous Coward · · Score: 0

    See subject & this link's undeniable truth (you LOSE, loser - grow up & get on topic) https://it.slashdot.org/comments.pl?sid=9982895&cid=53507817/ hosts work here. End of subject.

    APK

  81. Aw, you FAILED again as always, lol by Anonymous Coward · · Score: 0

    See subject & this link's undeniable truth (you LOSE, loser - grow up & get on topic) https://it.slashdot.org/comments.pl?sid=9982895&cid=53507817/ hosts work here. End of subject.

    APK