Bitcoin Forum
July 12, 2024, 06:52:59 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Be Alert] Lilocked Ransomware  (Read 136 times)
maxreish (OP)
Sr. Member
****
Offline Offline

Activity: 1330
Merit: 326


View Profile
September 09, 2019, 03:17:55 PM
Last edit: September 10, 2019, 12:02:01 AM by maxreish
 #1

Have you ever heard about Ransomware? This is indeed an interesting topic I have read in this site which really frustrates me.

Let's talk about the how this "Lilocked Ransomware is Targeting those websites and servers.

Believe it or not, there is something like new way of randsome bitcoin that is happening online.

How it works?
  • They are posibbly using "exploits" to attact and enter the site's server.
  • When a machine is infected, the ransomware will encrypt a file and then append the .lilocked extension to the file name. They will gonna put #README.lilocked folder that serves as a ransom note.

See images below:



When you opened it, this is the ransom note;



Their website' will be presented with a page asking them to enter their key.



After they entered the private key, there is an instruction on how the victim will gonna send .01 bitcoin to their address.



That's how it works. Attackers apology at the end and promised to return the encrypted data in exchange of .01 bitcoin or approximately $100. Wow, a new way of scamming and blackmailing online nowadays.

Until now, unfortunately there is no known way to decrypt files encrypted by Lilu.

Hope this won't happen to anyone here especially those who have  their own  websites.

If you want a detailed information, you can way check it here.
Code:
https://www.bleepingcomputer.com/news/security/lilocked-ransomware-actively-targeting-servers-and-web-sites/
Velkro
Legendary
*
Offline Offline

Activity: 2296
Merit: 1014



View Profile
September 09, 2019, 07:00:20 PM
 #2


That's how it works. Attackers apology at the end and promised to return the encrypted data in exchange of .01 bitcoin or approximately $100. Wow, a new way of scamming and blackmailing online nowadays.

This is not new. Its day after day more common attack on users because with crypto its easy to collect ransome. In past it was almost impossible to get money with such attack because how? With Paypal? Paypal would block such account in minutes.
BTW its Ransomware not Randsomware.
maxreish (OP)
Sr. Member
****
Offline Offline

Activity: 1330
Merit: 326


View Profile
September 10, 2019, 12:14:55 AM
 #3


-snip
This is not new. Its day after day more common attack on users because with crypto its easy to collect ransome. In past it was almost impossible to get money with such attack because how? With Paypal? Paypal would block such account in minutes.
BTW its Ransomware not Randsomware.

Thanks for correcting me. Just a typo error but it is also ransom not ransome. Anyway,  attackers find way to get some bitcoin from the victim.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!