If you post ads on Craigslist for short term employment, be aware that there’s a new malspam campaign that aims to distribute Sigma ransomware on the computers of unwary users.
By all outward appearances, the emails seem to come from Craigslist in response to ads posted in Craigslist’s “Gigs” section for short term employment. The emails will generally express interest in whatever job the user has posted and include a protected Word or RTF document which recipients will assume are resumes.
If the recipient enters the password to unlock the document, they’ll then be presented with a screen that asks them to enable the content in the document. Unfortunately, this is the step that dooms the user. The file isn’t a resume at all, but merely a delivery vehicle.
As soon as the content is enabled, the ransomware will be installed, the user’s files will be encrypted, and then will “helpfully” post a message explaining that the files have been encrypted, and explaining that to get access to them again, they’ll have to pay a $400 fee, which rises to $800 if the user waits longer than seven days to request the decryption key.
Unfortunately, there’s no known way to decrypt Sigma-encrypted files other than paying the ransom.
This is a new twist on a very old game. Even worse, it’s enjoying a relatively high success rate because people who post ads for short term employment on Craigslist expect to get responses from people they don’t know. They expect that those people will be sending resumes for review.
The “tell” is that when a potential employee sends you a resume, it’s almost certainly not going to be password protected. In this case, your best bet would be to reply to the sending and ask them to send you a non-protected resume if they’re genuinely interested in the job.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
The CEO of Trustico, a TLS certificate reseller based in the United Kingdom, finds himself at the center of a controversy that raises a number of disturbing questions about browser-trusted security certificates.
It looks like it’s going to be another bad month for Equifax. The company just can’t seem to get out of its own way.
Do you have a Mi-Cam in your home? Even if you don’t have kids, you may have one. They’re a highly popular, inexpensive means of keeping tabs on the comings and goings inside your home when you’re not around.
Recently, another “exotic character” bug was found in iOS. If someone sends this particular character (a special character that’s part of the Indian language pack) to your phone via any messaging app, it will not only crash your phone, but cause a variety of messaging apps to stop functioning.
There’s a new strain of the “Rapid Ransomware” making the rounds, and because of how it’s being transmitted, it’s destined to have a higher than average rate of infection. The new strain was first discovered by Derek Knight. It is disturbing because it claims to come from the IRS, and will feature subject lines like “IRS Urgent Message-164.”
Here’s a statistic that is as disturbing as it is frustrating. According to the latest “State of the Internet/Security” report for the fourth quarter of 2017, as published by Akamai, bot-traffic accounts for a staggering 43 percent of all login attempts. As bad as that figure is on its face, it’s far worse for companies in the hospitality industry, where the figure is an almost unbelievable 82 percent.
Hackers are picky about their victims. They’ll target just about any group or organization, including the 2018 Olympics.
Menlo Security just released their third annual “State of the Web” report and it’s not pretty. The headline finding is that 42% of the top 100,000 sites as ranked by Alexa are more dangerous than you think.