Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Tech support locker scam poses as failed Microsoft Update (malware wants $250 ransom)
The Register ^ | May 20, 2016 | John Leyden

Posted on 05/20/2016 12:14:54 PM PDT by dayglored

Cybercrooks have put together a new scam that falls halfway between ransomware and old school browser lockup ruses.

The new class of “tech support lockers” rely on tricking users into installing either a fake PC optimiser or bogus Adobe Flash update. Once loaded the malware mimicks ransomware and locks users out of their computers. Unlike Locky, CryptoWall and their ilk it doesn’t actually encrypt files on compromised Windows PCs, however.

Jérôme Segura, a senior security researcher at Malwarebytes, said “tech support lockers" represent a class of malware more advanced than browser locks and fake anti-virus alerts of the pre-ransomware past.

"This is not a fake browser pop up that can easily be terminated by killing the application or restarting the PC,” Segura writes in a blog post. “No, this is essentially a piece of malware that starts automatically, and typical Alt+F4 or Windows key tricks will not get rid of it."
One strain of tech support locker employs a subtle piece of social engineering trickery by waiting until a users restarts their computer before confronting users with a fake Windows update screen. Users are told their computers can’t be restarted normally supposedly because of an “expired license key”. Thereafter a screen locks a user out of their computer in an attempt to trick marks into phoning a support number, staffed by scammers.

Victims are told that their problems can be resolved, for a fat fee of $250, Malwarebytes discovered.

The particular strain of malware - spotted and documented by independent White Hat security researcher “TheWack0lian” - marks a evolution in tech support scams, Malwarebytes’ Segura warns.

“In comparison to fake (but mostly harmless) browser alerts, these Windows lockers are a real pain to get rid of and until you do so, your computer is completely unusable.... This increased sophistication means that people can not simply rely on common sense or avoid the typical cold calls from 'Microsoft'. Now they need to also have their machines protected from these attacks because scammers have already started manufacturing malware tailored for what is essentially plain and simple extortion over the phone,” he writes.

Miscreants have already begun to flog these types of lockers on Facebook, a sign that scams of this type have reached script kiddie level and are therefore likely to become commonplace in future. Previous scams along the same lines, although less sophisticated, include a BSOD ruse that surfaced last September.

“There is an entire ecosystem to distribute these tech support lockers, which includes bundling them into affiliate (Pay Per Install) applications,” Segura concludes.

More commentary on the scan can found in a post from security blogger David Bisson here.

Bot-note:

A keyboard combination to disable the tech support locker malware by holding Ctrl+Shift while pressing the S key, was discovered by TheWack0lian. The same white hat discovered hardcoded values for the ‘product key’: “h7c9-7c67-jb” or “g6r-qrp6-h2” or “yt-mq-6w” which may offer a means to recover from infection without paying scammers, at least in the case of this one particular strain of malware.


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: locker; malware; windows; windowspinglist
B@stards. Vlad The Impaler had the right idea.
1 posted on 05/20/2016 12:14:54 PM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
Windows Update ruse - MALWARE ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 05/20/2016 12:15:40 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Why can't law enforcement track the phone number back to a person? I've NEVER heard of one of these bastards being prosecuted.
3 posted on 05/20/2016 12:17:56 PM PDT by grobdriver (Where is Wilson Blair when you need him?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: grobdriver

Most of them are in Russia or China.

I wish I could get my hands on just one of them. There would be medieval torture methods involved.


4 posted on 05/20/2016 12:23:15 PM PDT by unixfox (Abolish Slavery, Repeal the 16th Amendment)
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored

Image
Your
Machine
Beforehand


5 posted on 05/20/2016 12:27:12 PM PDT by TomServo
[ Post Reply | Private Reply | To 1 | View Replies]

To: unixfox

From the cheesy movie Ransom:

Tom Mullen: [on live TV] The whole world now knows... my son, Sean Mullen, was kidnapped, for ransom, three days ago. This is a recent photograph of him. Sean, if you’re watching, we love you. And this... well, this is what waits for the man that took him.

This is your ransom. Two million dollars in unmarked bills, just like you wanted. But this is as close as you’ll ever get to it. You’ll never see one dollar of this money, because no ransom will ever be paid for my son. Not one dime, not one penny. Instead, I’m offering this money as a reward on your head. Dead or alive, it doesn’t matter. So congratulations, you’ve just become a two million dollar lottery ticket... except the odds are much, much better. Do you know anyone that wouldn’t turn you in for two million dollars? I don’t think you do. I doubt it.

So wherever you go and whatever you do, this money will be tracking you down for all time. And to ensure that it does, to keep interest alive, I’m running a full-page ad in every major newspaper every Sunday... for as long as it takes. But... and this is your last chance... you return my son, alive, uninjured, I’ll withdraw the bounty. With any luck you can simply disappear. Understand... you will never see this money. Not one dollar. So you still have a chance to do the right thing. If you don’t, well, then, God be with you, because nobody else on this Earth will be.


6 posted on 05/20/2016 12:29:45 PM PDT by rockrr (Everything is different now...)
[ Post Reply | Private Reply | To 4 | View Replies]

To: TomServo
Image Your Machine Beforehand

Bingo. Do it religiously once per week if not, more. I use Macrium Reflect and it is awesome. For my Linux, the need isn't so severe but it's just as easy.

7 posted on 05/20/2016 12:41:51 PM PDT by Bloody Sam Roberts (#BlackOlivesMatter)
[ Post Reply | Private Reply | To 5 | View Replies]

To: dayglored

Find where the number leads and kill everyone there.


8 posted on 05/20/2016 12:49:48 PM PDT by soycd
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bloody Sam Roberts
I build images of several installs

1). Base (basically factory)
2). Office Suite
3). Development
4). Daily
5). Games

Each image build incrementally so I can restore at any point. My personal files themselves reside on another drive. So when I restore the "C" Drive, my personal files are untouched.

9 posted on 05/20/2016 12:55:22 PM PDT by TomServo
[ Post Reply | Private Reply | To 7 | View Replies]

To: TomServo

That, sir is the voice of experience.


10 posted on 05/20/2016 2:13:02 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 9 | View Replies]

To: dayglored

Install Adblock Plus.

Damned Malvertising gone for good.


11 posted on 05/20/2016 3:13:50 PM PDT by goldstategop ((In Memory Of A Dearly Beloved Friend Who Lives In My Heart Forever))
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I hope somebody empties an entire magazine into one of these maggots one day.


12 posted on 05/20/2016 7:21:50 PM PDT by Tolerance Sucks Rocks (0bama's insane rantings prove that power deludes, and absolute power deludes absolutely.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 3D-JOY; abner; Abundy; AGreatPer; Albion Wilde; AliVeritas; alisasny; ALlRightAllTheTime; ...

I’d like to fry one of these creeps and then serve him to his buddies for dinner.

PING!


13 posted on 05/20/2016 7:24:42 PM PDT by Tolerance Sucks Rocks (0bama's insane rantings prove that power deludes, and absolute power deludes absolutely.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: sauropod

.


14 posted on 05/20/2016 8:24:34 PM PDT by sauropod (Beware the fury of a patient man.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: left that other site

FYI


15 posted on 05/21/2016 8:25:11 AM PDT by MEG33 (God Bless America And Our Troops***DEFEAT HILLARY)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MEG33

Wow...I got that fake Adobe Flash “Upgrade”

I got suspicious when they asked for a password. Adobe never asked for that before.


16 posted on 05/21/2016 8:28:18 AM PDT by left that other site (You shall know the Truth, and The Truth Shall Set You Free.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: left that other site

I know...I love being on this ping list...Some of it is way beyond my computer savvy but many are very helpful to me. I save ones like this to a file.


17 posted on 05/21/2016 8:35:04 AM PDT by MEG33 (God Bless America And Our Troops***DEFEAT HILLARY)
[ Post Reply | Private Reply | To 16 | View Replies]

To: left that other site

Like you...I won’t click on anything that looks hinky.

It’s better to go to the main site and update from there.


18 posted on 05/21/2016 8:43:25 AM PDT by MEG33 (God Bless America And Our Troops***DEFEAT HILLARY)
[ Post Reply | Private Reply | To 16 | View Replies]

To: MEG33

It’s a Jungle out there!


19 posted on 05/21/2016 9:15:22 AM PDT by left that other site (You shall know the Truth, and The Truth Shall Set You Free.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: MEG33
> I love being on this ping list...Some of it is way beyond my computer savvy but many are very helpful to me. I save ones like this to a file.

Thanks, Meg33, you just made my day! :-)

20 posted on 05/21/2016 4:48:09 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 17 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson