Malware News Fantom Ransomware Encrypts your Files while pretending to be Windows Update

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
VIDEO BY @CyberSecurity GrujaRS : Video Review - Fantom Ransomware - Demonstration of attack

A new ransomware called Fantom was discovered by AVG malware researcher Jakub Kroustek that is based on the open-source EDA2 ransomware project. The Fantom Ransomware uses an interesting feature of displaying a fake Windows Update screen that pretends Windows is installing a new critical update. In the background, though, Fantom is secretly encrypting a victim's files without them noticing.


Unfortunately, there is no way to currently decrypt the Fantom Ransomware and usual methods for get EDA2 based ransomware keys are not available with this variant. For those who wish to discuss this ransomware or need support, you can use the Fantom Ransomware Help Support Topic.

Fantom disguises itself as a Critical Windows Update
The developers behind the Fantom Ransomware make an extra effort to hide it's malicious activity by pretending the program is a critical update for Windows. To add legitimacy, the file properties for the ransomware states that it is from Microsoft and is called critical update.
file-properties.png

When executed, the ransomware will extract and execute another embedded program called WindowsUpdate.exe that displays the fake Windows Update screen shown below. This screen overlays all of the active Windows and does not allow you to switch to any other open applications.


Read more: Fantom Ransomware Encrypts your Files while pretending to be Windows Update
 

davidp

Level 1
Verified
Aug 16, 2016
26
I'm a bit confused...where are the signature details that usually accompany the file's properties? Have they successfully compromised Microsoft and signed legitimately? Or is this example from a system that predates that mechanism?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top