Locky Ransomware Distribution Network Hacked to Show Warning Message Instead

Exterminator

Level 85
Thread author
Verified
Top Poster
Well-known
Oct 23, 2012
12,527
The practice of hacking malware botnets and then replacing their payloads with pro-user content is starting to become the norm, with another of these incidents being reported by the team from F-Secure.

The company says that one of its security researchers stumbled upon a weird sample coming from the server network (botnet) from which most of the Locky ransomware-carrying spam is sent out.

The file was a ZIP archive containing a JavaScript file. If the user double-clicked this JavaScript file, the script would download in normal circumstances the Locky ransomware and launch it into execution, effectively encrypting their files.

This time around, the F-Secure researcher, named Päivi, discovered that, instead of Locky, this file was downloading something different, also launching it into execution.

It appears that someone hacked the Locky distribution network and replaced the Locky ransomware payload with a benign file that showed a simple popup warning users not to open email attachments from untrusted sources (screenshot below).

"You are reading this message because you have opened a malicious file," the popup reads. "For your safety, don't open unknown emails attachment."[sic]

Something like this happened before last February, when somebody hacked the Dridex botnet to deliver a version of the Avira antivirus installer instead of the Dridex banking trojan, and then again last month with the Locky network, when someone replaced the ransomware with an empty file that read "STUPID LOCKY."
 

Jack

Administrator
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
That's a modern day hero. Can't believe that in 2016, people are still falling for these scam emails. Ransomware has become a huge problem, and this Locky malware is one of the most active out there. I do think that the FBI and EUROPOL should take some measures, as this "hacks" can only a few people.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top