PewCrypt Ransomware Locks Users' Files and Won't Offer a Decryption Key Until - and Unless - PewDiePie's YouTube Channel Beats T-Series To Hit 100M Subscribers (zdnet.com)
The battle between PewDiePie, currently the most subscribed channel on YouTube, and T-Series, an Indian music label, continues to have strange repercussions. In recent months, as T-Series closes in on the gap to beat PewDiePie for the crown of the most subscribers on YouTube, alleged supporters of PewDiePie, in an unusual show of love, have hacked Chromecasts and printers to persuade victims to subscribe to PewDiePie's channel. Now ZDNet reports about a second strain of ransomware that is linked to PewDiePie. From the report: A second one appeared in January, and this was actually a fully functional ransomware strain. Called PewCrypt, this ransomware was coded in Java, and it encrypted users' files in the "proper" way, with a method of recovering files at a later date. The catch --you couldn't buy a decryption key, but instead, victims had to wait until PewDiePie gained over 100 million followers before being allowed to decrypt any of the encrypted files. At the time of writing, PewDiePie had around 90 million fans, meaning any victim would be in for a long wait before they could regain access to any of their files. Making matters worse, if T-Series got to 100 million subscribers before PewDiePie, then PewCrypt would delete the user's encryption key for good, leaving users without a way to recover their data.
While the ransomware was put together as a joke, sadly, it did infect a few users, ZDNet has learned. Its author eventually realized the world of trouble he'd get into if any of those victims filed complaints with authorities, and released the ransomware's source code on GitHub, along with a command-line-based decryption tool.
While the ransomware was put together as a joke, sadly, it did infect a few users, ZDNet has learned. Its author eventually realized the world of trouble he'd get into if any of those victims filed complaints with authorities, and released the ransomware's source code on GitHub, along with a command-line-based decryption tool.
Into the gaschamber with PewDiePie. He (and the *ahem*certain people*cough* who artificially made him a big "star") has raised a whole generation of kids who are now literally *unbearable*, and who are growing up to become horrible human beings, even considering today's scum. I'm serious about wanting to execute this man, in a very slow and painful way.
At what point, if any, do we start holding PDP responsible for the actions of his fans?
Perhaps I've missed it (and it's a good chance I have as I don't follow him) but I don't recall seeing where he's spoken out about the illegal activities being done in his name (hacking, encrypting, murder, etc) and in the USA it seems, if you're not condemning these actions, that's tantamount to condoning them...
So rise up, all ye lost ones, as one, we'll claw the clouds.
I was never a fan (not being a 13 year old girl when he broke) but somewhere along the line he pivoted to attracting the Alt-Right viewers and seemed to have gone off the deep end. Then again I was never a fan, maybe he always was like this. At any rate the fans he's attracting were already scary and that was before this and that mess in New Zealand.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
Even funnier, I'm going to subscribe to T-Series now because of the retards that did this.
Kill yourself.
I'm not sure its the kind we want, but... whatevs!
It wouldn't suprise me if this racist clown was 100% involved in distributing the malware.
PewDiePie should just die.
No big loss.
No need to support anyone who not funny and whose comedy is the lowest common denominator. Guess why children like him. They have no taste.
http://progressquest.com/spoltog.php?name=Son+Of+Son+Of+DarkRookie
To get a negative subscription?
What could possibly go wrong?
I have seen on Twitter recently that PewDiePie is "alt-right", but as is usual with anything labeled "alt-right" that is Fake News.
What the hell have you seen that would make him alt-right? I don't watch his videos much but in the few I have seen there is zero political content of any kind. He does meme reviews for crying out loud!
I am pretty sure he has irked some people, these days anyone who is mad at you for anything simply labels you "alt-right". Don't propagate slander and lies.
P.S. if you don't realize the NZ shooter simply used his name to try as a kind of trolling, you've not been paying attention to what happened there.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
It's not the loonies killing in the name of religion. It's not the fact that people are willing to do long term damage to the public, the environment, or even themselves in the search for short term gains.
It's shit like this that makes me say sod it. Let the meerkats have a go. Or squid, they're pretty smart.
Confucius say, "Find worm in apple - bad. Find half a worm - worse."
And using Youtube as a platform for payment doesn't change that.... I'd be surprised if this doesn't violate Youtube's TOS, and they can suspend or even terminate the account.
File under 'M' for 'Manic ranting'
At some point, he did a stunt that contained some pretty anti-Semitic content
True but that would make him a Democrat (see: Trump and Golan heights for the opposite of an anti-semite).
Alt-righters gravitated toward him because they've been in a similar position
Almost the entire right support Israel and jews generally. Again, for anti-semitic hatred you can look almost everywhere on the Democrat side of things now. There are some that are not, but they are being drowned out and sidelined at the moment.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Whether responsible originally or not, this character now is liable. Every firm damaged by this should sue him personally. This whole affair is absolutely crazy and shows the problem with new media advertising. Funding those sources that collect attention as a means to spread your own message doesn't work anymore. Considering views and clicks as expressions of commercial intent and rewarding whatever mechanism produces them is broken. There is no connection between purchases and the actions of a horde of children at computers, not even what was used by old toy commercials on broadcast tv. Every avenue open means the avenues are in the worst degenerative competition to outrage constantly to produce views and clicks while disavowing all responsibility. The world doesn't work like that though, there are avenues for recompense.
Then kill yours already.
I have no idea WTF a pew-die-pie is -- something to do with laser pistols and dessert? -- but I am getting really sick of seeing references to subscribing to it. Quick drawing attention to it and it'll probably wither away.
problem solved.
If you can't take the heat, then don't sudo apt-get install malware and type your password in the kitchen. I can abstain from making the effort to install malware much faster than I can watch even one video, much less ten million of them.
I fucking swear, every single time Slashdot covers malware, the editors and authors always take the position that users should install malware before they think about whether it's a good idea or not, rather than after. Life pro tip: think about whether you really want the malware, then if and only if you're sure you want the malware, should you install it. If it doesn't sounds like something you want, just don't do it. Why would you want to encrypt all your files with an unknown key, where you're not even allowed to decrypt until after you pay or someone else does something? WTF could you possibly get out of that?!
Shit troll is shitty. News at fucking 11. What the fuck is wrong with you?
Oh you poor wittle snowflake. The comedians make fun of your wittle weader and you need your diapy changed.
In case you didn't know, no one is screaming for people to subscribe to Colbert or one of the Jimmys before they go killing people. You're seriously deranged.
It really shows how little/poorly understood he and his fans are... Or why they are the way they are lol.
Old media hates him for pointing out their BS and happily pushes the line of him being "alt right" while anyone that knows the guy, knows he's a big softie. creating a happy cycle of people realizing the old media is spin doctoring BS and then exploring "alternative" things. Including some not so nice stuff.
He literally burned a paper model of Trump in effigy. This makes him "alt-right"?
He made some joke videos akin to the guy who's dog raised its paw at a Hitler video. This was in response to continued media labelling him as Nazi / Racist / Alt-Right. So he agreed and amplified in a harmless trolling way. He disavowed the claims then sarcastically ended the vid with a brief clip of him wearing a military uniform and nodding to a random Hitler rant (which was about bankers). This type of response is known as "agree and amplify" or "reductio ad absurdum", but the left ran with the "See! he's really a Nazi!"
-----
Now, that was a discussion for the normies. Bros, we know the truth. Disney is full of pedos. Pewds had his eyes opened to this while they courted him as a personality. So he destroyed his reputation on purpose rather than sell his soul to the devil: We all know to get famous in Hollywood or music industry you have to let them video you killing and/or raping a kid. Pewds became redpilled. The media lashout is because the pedocracy is against him... and also, because Hitler is Pewdiepie.
This seems to be a point of contention, but the Israeli government is not the final end all, be all of Jewishness. I'll remind everybody of Trump's "Good people on both sides" comment and that he cut back on enforcement of anti-Hate and anti-Domestic Terrorism. He didn't do that for the sake of the Muslims.
The right does not support Jews or Israel, _Evangelicals_ support Israel because their reading of their holy books is that Jesus will take them to paradise when all the Jews are brought to Israel. Evangelicals aren't really right wing, but they will vote for the GOP because the GOP will let them do what they want as long as they vote for their tax cuts in return. Before the GOP figured this out the Evangelicals were buddy buddy with the left wing because they were working class people who wanted better pay, educations for their kids, safe work environments and clean air. They traded that in for concessions on social issues (Abortion, Israel, Prayer in Schools, etc). This kind of wedge issue creation is how American politics (and politics in General) work.
The "right" generally accepts all comers as long as you're willing to sign on for weak regulation, low taxes and few worker protections. This is why Fascists end up on the right here in America (instead of being ostracized by both left and right as the nut jobs they are). The same goes for Racists and literal Nazis. The American right will let anyone into their tent as long as you support their economic platform of low taxes and weak worker protection.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
all but one. Several left wingers on YouTube went through the list before hand and found a ton of Alt-Right guys, including some really nasty ones. Look up a guy named Cult of Dusty on YouTube and he talks about some of the worst ones. Several white supremacists and extreme right wing folk were in there.
I don't think he himself is a white supremacist, but I also don't think he put any effort into avoiding them. For someone as visible as he is that's just bad all around.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
has certain social responsibilities (note: social responsibilities, not legal ones). One of those is fostering a discourse and an environment that is overall a net positive.
I haven't watched PDP, but he's had a mess of nasty controversies around racial themes. Ones he was pretty obviously doing on purpose because, as the saying goes, there's no such thing as bad publicity. And he was right. The backlashes have all blow over and he's kept the dough rolling in. But at a cost. That cost is normalizing a certain form of behavior. When it's out in the open like that and nobody's getting censored (that's censored in the social sense, not the legal/governmental sense) it because acceptable.
That's sort of the problem. It's the old "boil a frog" analogy. Yeah, you can't really boil a frog, but it's easy to convince folks you can because it's a relatable thing for humans. The idea that you can get accustom to something awful or even deadly.
We've got too many examples of horrifying things being normalized bit by bit to ignore this. The world at large should call PDP on his racist bullshit whether he means it or not and send him packing. He's not starting an honest discussion of racial issues. He's just a rancid troll winding angry kids up and sending them off.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
right here
For those who don't want to be bothered watching the video (or can't stand Cult of Dusty, which I can't really blame you for), PDP had a large number of alt-right personalities he was following and after the New Zealand shooter he emptied his followers list.
PDP may or may not actually believe any of the things the alt-right does. But he absolutely uses the movement and it's fans to his advantage. The controversial things he's done have almost exclusively appealed to the alt-right.
Like a lot of YouTubers he's figured out that the alt-right is a powerful engine for increasing views and ad revenue. But feeding off that isn't a one way street. He's normalizing and legitimizing the worst aspects of that community. And not just him. Other YouTubers like Sargon of Arkad, JonTron and Ben Shapiro are doing the same. Go look up some videos from Contrapoints, Three Arrows and hbomberguy on the subject. They're far better than anything I could type.
There's an entire engine on YouTube, Twitter and Facebook dedicated to exploiting angry, bitter, jobless young men for ad revenue and Pateron donations. I'm bloody sick of it. It's dangerous as fuck. Eventually a real demagogue will come along and organize them into brown shirts.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
Amazing. Just look at all these fucking goobers desperate to tie their completely uninteresting little lives and egos to a Youtube 'star' who wouldn't piss on them even if they begged him to.
I'm convinced more than ever that what this world needs is a damn good plague.
Just cruising through this digital world at 33 1/3 rpm...
I'm going to subscribe to T-Series now because of the retards that did this.
How do you know this was not the intent of the people that made the malware?
Think about it, who benefits most from malware like this... most people would think as you do.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Sigh, /. is dead. It's like none of the posters even looked at the code.
For anyone who's interested, the encryption used here is very poor. He leaves the mode and padding unspecified for both the asymmetric (RSA) and symmetric (AES) encryption operations. That causes the provider defaults to be used. In the case of the RSA step that's not terrible, since every provider I'm aware of uses PKCS#1 v1.5 padding. This isn't great, since PKCS#1 v1.5 is vulnerable to an adaptive chosen ciphertext attack, but in this usage that doesn't really matter.
The bigger problem is that AES typically defaults to ECB mode. Using ECB means that any repeated 16-byte blocks of plaintext will encrypt to identical 16-byte blocks of ciphertext. This can often expose enough structure to allow the file contents to be partially recovered. It's particularly bad in this case since the same key is used to encrypt all of the files. If AES were in any way vulnerable to brute force, this would almost certainly provide many "cribs" (known plaintext/ciphertext pairs) which could be used to discover the key and decrypt everything else. AES-256 is not, however, vulnerable to brute force, and won't be until computers are made of something other than matter and occupy something other than space (anyone catch the reference?).
Overall, I suppose the chosen encryption was adequate to the task, but it was very sloppy.
Do you think he'd accept a pull request to fix it up?
The minimum required changes are small. I'd use "RSA/ECB/OAEPWithSHA-256AndMGF1Padding" for the RSA operation, just because, and "AES/GCM/NoPadding" for the AES op. It would also be necessary to get the IV (let the provider generate it) and prepend it to each encrypted file. The files would be 28 bytes larger (12 for IV, 16 for tag), but secure.
Also, I'd process files in chunks rather than reading a whole file into memory and then encrypting and writing it back out. It could then handle files of any size. His code just skips any files larger than 20 MB. That's actually the biggest flaw in the implementation; given file sizes today, lots of stuff would just be skipped. All of my RAW photos would be safe, for example. The JPEGs would get encrypted, but who cares about them?
Oh, one more problem: Most systems these days don't overwrite in place, so the plaintext file will be left on the drive, available for recovery. Granted that recovery is not trivial, but still, the data will be there. Fixing this would require doing something like filling the drive with garbage files, forcing the drive to overwrite all free blocks. Overwriting multiple times might be a good idea, too, though that's probably not necessary. Some systems offer free space shredding as a feature; on those that could be used to ensure destruction of the plaintext.
Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
"can't really boil a frog"
Ok, so what happens to a frog when it's in a pot of boiling water that's different than, say a hot dog? Because I *know" I can boil hot dogs.
behind the scenes it's Reptile People all the way down.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
He did that because the shitheads that follow people like Cult of Dusty were sending PewDiePie's follows death threats, so PewDiePie replaced his list with a single link to K-Pop band BTS as a half joke, half attempt to sic millions of teenage fangirls onto said shitheads.
Before this, PewDiePie also followed plenty of people who are not right wing, including Laci Green, Boogie2988, James Charles, and the aforementioned BTS. It's almost like he was using Twitter to follow interesting people regardless of whether or not he agreed with them, just like everyone else.
Rob
I think that where there's a 'social responsibility', there's a very 'socially responsible' person that decided what it was.
Politics; n. : A religion whereby man is god.
The PewCrypt Ransomware requires the Java Runtime Environment (JRE) to be present on the infected computer to carry out its attack. Java has long been notorious for it's security vulnerabilities. It's right up there with Adobe Flash for worst security ever. People who run JRE in 2019 deserve whatever happens to their computers.
It's Hackers! With Hacks! They've been Hacking!
It's like holding smurfs accountable for smurfing. "Everybody knows" you just can't do that.
Which is why breathless idiots shout "hacked! hacking! hackers!" anytime something funny happens and they can't readily attribute it to someone in specific, or they want this to be the case.
I don't normally agree with mych you day, but this is right on the money. Also made me laugh. MOD ARENT UP!
SJW n. One who posts facts.
I cannot understand why people waste any time on this PewDiePie asshole. He is a known racist and anti-semite. But I bet that the PewDiePie shit is the same phenomenon that gave us President Trump, and other recent dictators like in Brazil, Italy, and Hungary. I hope this fad of watching videos with stupid commentary by assholes like PewDiePie ends soon. Anyone who watches his crap is by definition an idiot.
He wrote a virus, it got out and infected people. He should still be arrested and tried.
I'll speculate that it was more of a "follow me and I'll follow you" tit-for-tat strategy that is employed by "influencers". It is the famous people crowd's currency. You go on someone's podcast and say how great they are, and they say how great you are. It is all just advertising, paid for by in-kind contributions.
If you violate the contract, then they retaliate in kind. Hence the celebrity twitter wars of hate. It is simple tit-for-tat game theory.
So if someone with a big list of followers follows you, then you follow them back. Simple as that. You don't even have to read any of their stuff.... in fact, you probably couldn't read it all, not if you are following hundreds or even thousands of people.
"That cost is normalizing a certain form of behavior. "
making edgy jokes? Uh oh. The Joke Nazi's are out goose stepping their way into normalizing fascist behavior again. Let's round up all the comedians and put them in camps where they can concentrate on Correct Funny Jokes that are approved by the Central Committee of Approved Comedians and Jokes. They have cookies!
"He's not starting an honest discussion of racial issues"
Obviously. Was Monty Python? Was CK Louis? Was Dave Chapelle? Does everything have to "start an honest discussion"? What ever happened to just making jokes for the sake of jokes. If you find it funny great if not move on.
You sound like a puritan nanny upset the kiddies listen to rap in the 90's. Or upset about D&D spreading satanism in the 80's.
wutz a pew die pie, and why do we care?
on their ties to White Supremacy and Neo-Nazis. The Alt-Right has been using dog whistles to cosy up with those two groups since day 1 without taking any flack to speak of. It's both dangerous and disingenuous to allow that to go on.
What I'm saying is this: The Alt-Right are not your friends. They're a friendly face on the same Authoritarian arm of the right wing that's been around since the 20s. They exist specifically to legitimize and normalize something that was rightly recognized as horrific post WWII and the Civil Rights movement.
Now, you can find pages and pages of posts, documents and hours of video of their leadership talking about this, but you have to plow through a lot of crap to get to it. In the old days we had professional journalists doing that work. Nowadays it's YouTubers.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
hopefully using our reasoning abilities instead of emotion or (worse) authority. But when you just throw you're hands up and say "Do what thou wilt shall be the whole of the law" you're not being a free speech warrior, you're just trying to absolve yourself of responsibility for your actions (or lack thereof).
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
via humor that doesn't actually lampoon them, but makes them relatable. PDP isn't actively trying to do this, btw. If he was it'd be easier to spot him for what he's doing. Instead he's responding to whatever gets him attention and views.
Making fun of Nazis ala Monty Python is old hat. If PDP tried that folks would shrug and go watch Monty Python. If they wanted blue humor CK & Chapelle both do it better. So he just flies Nazi flags and waits for the views to roll in from the controversy. Meanwhile he's made plain Nazi iconography just a little more normalized in society at large. He's made it hard to tell the difference between "just doing it for the lulz" and actual Nazis. And he's given the actual Nazis cover, many of whom after the "Unit the Right" lobby used the same excuse of "the lulz" as PDP did.
There were never any actual rappers using their music to form gangs (there was a bunch of drug money laundering going on though) and there weren't any real Satanic cults using D&D to lure helpless victims. There _are_ Nazis using PDP and other YouTubers like him to recruit.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
Comment removed based on user account deletion