Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Wait, STOP: Are you installing Windows 10 or ransomware? (CTB-Locker masquerading as Win10 upgrade!)
The Register ^ | July 31, 2015 | Iain Thomson

Posted on 07/31/2015 7:14:01 PM PDT by dayglored

People aren't good at waiting for stuff, and with, computer users queueing up to download Windows 10, ransomware purveyors have started to move in.

Cisco's security team has noticed a new spamming campaign attempting to spread the CTB-Locker ransomware using emails purporting to come from Microsoft, telling people they are ready to download Windows 10.

The emails mimic the actual Windows 10 messages Redmond is sending out (with some minor text mistakes) and have spoofed the originating address to read as update@microsoft.com, although the sender's IP address can be traced back to Thailand. There's also a Microsoft disclaimer, and a message claiming the files have been cleared as virus-free by Mailscanner.

A 734KB attachment included in the emails claims to be a Windows 10 installer but actually contains the ransomware, which sets to work encrypting documents, media files, and anything else that might be useful to the hapless people who double-click on it. Analysis of the source code is ongoing, but the elliptic curve encryption algorithm used looks sound.

"I suspect this one is going to be an absolute bastard to deal with because they use good asymmetric encryption," Craig Williams, security outreach manager of Cisco's Talos team told The Register.

(Excerpt) Read more at theregister.co.uk ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: ransomware; windows10; windowspinglist
Navigation: use the links below to view more comments.
first previous 1-2021-29 last
To: dayglored

Nasty.

Being the impatient person that I am, I got tired of waiting for my reserved copy, so I just downloaded it directly from Microsoft.

http://www.microsoft.com/en-us/software-download/windows10

Lovely OS. I’d describe it as a better version of 7.


21 posted on 07/31/2015 8:19:24 PM PDT by chris37 (Heartless)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SkyDancer

My Windows System page says Windows 10 Home,

but when I run Belarc Advisor it says:

Windows 8.1 (x64) (build 9600)
Install Language: English (United States)
System Locale: English (United States)
Installed: 7/30/2015 7:07:15 PM.

Cant seem to find TabWorks.


22 posted on 07/31/2015 8:21:21 PM PDT by Delta 21 (Patiently waiting for the jack booted kick at my door.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Dr.Deth

Thailand?


23 posted on 07/31/2015 9:12:49 PM PDT by dayglored (Meditate for twenty minutes every day, unless you are too busy, in which case meditate for an hour.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: SkyDancer

How is vista working out for you? I heard that was a pretty lousy OS.

Full disclosure: I use Windows 7 on PC and iOS on iPhone.


24 posted on 07/31/2015 10:18:13 PM PDT by Tolerance Sucks Rocks (Democrats and GOP-e: a difference of degree, not philosophy)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Delta 21

Open a command prompt and type - winver


25 posted on 07/31/2015 11:03:24 PM PDT by VeniVidiVici (American Taliban - The Democratic Party)
[ Post Reply | Private Reply | To 22 | View Replies]

To: Tolerance Sucks Rocks

Vista works good on my main laptop and I use Windows 7 on my notebook. Both work fine.


26 posted on 08/01/2015 6:30:12 AM PDT by SkyDancer ("Nobody Said I Was Perfect But Yet Here I Am")
[ Post Reply | Private Reply | To 24 | View Replies]

To: dayglored
"I suspect this one is going to be an absolute bastard to deal with because they use good asymmetric encryption," Craig Williams, security outreach manager of Cisco's Talos team told The Register.

Is this Chinese crap?

27 posted on 08/01/2015 7:42:31 AM PDT by GOPJ (They are not undocumented and they are not immigrants. They are illegal aliens. Lurkinnamloomin)
[ Post Reply | Private Reply | To 1 | View Replies]

To: GOPJ
> Is this Chinese crap?

It could be, but the Chinese tend to be sneaky and quietly steal information for longer term state use. This encryption scam is more immediate and is for financial gain, so I suspect non-state criminals with shorter term goals. But that's just a guess.

28 posted on 08/01/2015 7:51:12 AM PDT by dayglored (Meditate for twenty minutes every day, unless you are too busy, in which case meditate for an hour.)
[ Post Reply | Private Reply | To 27 | View Replies]

To: dayglored

Thanks dayflored - - nice logic...


29 posted on 08/01/2015 8:41:38 AM PDT by GOPJ (It takes a village of aborted dead babies to buy a Lamborghini - freeperblackdog)
[ Post Reply | Private Reply | To 28 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-29 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson