RATE Group | This old ransomware has been revamped as Bitcoin-stealing malware
35706
post-template-default,single,single-post,postid-35706,single-format-standard,ajax_fade,page_not_loaded,,qode_grid_1300,side_area_uncovered_from_content,footer_responsive_adv,qode-content-sidebar-responsive,qode-child-theme-ver-1.0.0,qode-theme-ver-13.3,qode-theme-bridge,wpb-js-composer js-comp-ver-7.9,vc_responsive
 

This old ransomware has been revamped as Bitcoin-stealing malware

This old ransomware has been revamped as Bitcoin-stealing malware

[ad_1]

An old form of ransomware has been re-purposed to steal bitcoin by altering the addresses of wallets and redirecting payments into accounts owned by the attacker.

Little of the malicious code has been changed so a number of security products will still identify it as the file-locking malware, despite this version’s new role in outright stealing cryptocurrency.

Detailed by researchers at Fortinet, this Bitcoin stealing campaign has its origins in Jigsaw – a form of ransomware which appeared in April 2016 and infamous for displaying the face of horror film antagonist it is named after.

The source code of Jigsaw has been available for a long time and is widely distributed online, so the attack is unlikely to be the work of the original ransomware author because anyone with knowledge of C# code could theoretically tailor the malware to their own ends.

In this instance, the author is looking to take advantage of the popularity of…

[ad_2]

Source link