There’s a new strain of the “Rapid Ransomware” making the rounds, and because of how it’s being transmitted, it’s destined to have a higher than average rate of infection. The new strain was first discovered by Derek Knight. It is disturbing because it claims to come from the IRS, and will feature subject lines like “IRS Urgent Message-164.”
The body of the email then goes on to say that the recipient owes some amount of money in real estate taxes, and “helpfully” includes instructions for how to settle in the attached file. Inside the zipped file, the user will find a word document. You’ll need to click on “Enable Editing” to see the file, and unfortunately, the moment you do, you’re doomed. “Rapid” will scan the target computer for data files and encrypt them, appending each with the “.rapid” extension.
As soon as the malware finishes encrypting your files, it will automatically open “Recovery.txt” which will display details on how much you’ll have to pay the hackers to get your files back. Unlike most other ransomware strains, this one will configure itself to start every time you login to the computer, so if you pay the ransom to get access to your files again, but fail to completely remove the malware, you’ll be facing the same problem the very next time you use the machine.
Observant users will take note of the fact that the email address is not a .gov and likely not be taken in. Unfortunately, many people will look no further than the subject line and immediately begin following the instructions contained in the email, which is obviously the reaction that the hackers are hoping for.
As ever, protecting yourself from threats like these comes down to two things: Education and vigilance.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Here’s a statistic that is as disturbing as it is frustrating. According to the latest “State of the Internet/Security” report for the fourth quarter of 2017, as published by Akamai, bot-traffic accounts for a staggering 43 percent of all login attempts. As bad as that figure is on its face, it’s far worse for companies in the hospitality industry, where the figure is an almost unbelievable 82 percent.
Hackers are picky about their victims. They’ll target just about any group or organization, including the 2018 Olympics.
Google is poised to make an important change to its Chrome browser beginning in July 2018.
Image theft is one of the biggest problems on the internet. If you’re a photographer, you’ve almost certainly lost money because people find your work online and make a copy of it rather than paying for the right to use it.
Menlo Security just released their third annual “State of the Web” report and it’s not pretty. The headline finding is that 42% of the top 100,000 sites as ranked by Alexa are more dangerous than you think.
Microsoft is getting tough on so-called “registry cleaners”, and it’s about time. The company recently announced a planned change to Windows Defender (the anti-malware program that comes standard with every Windows installation). The change will see to the deletion of an increasing number of these registry cleaners. It’s a great move, and the company deserves credit for it, but there’s a catch. This type of software has been around for decades. So the move, as welcome as it is, comes very late in the game.
Sophos has released the results of their annual “State of Endpoint Security Today”, and it doesn’t paint a pretty picture. A full 54% of companies surveyed reported having been hit by a ransomware attack in 2017. Another 31% reported that they expect to be on the receiving end of such an attack in the near future.
Security researchers from around the web are reporting finding an increasing number of instances of proof of concept (PoC) code that incorporates the recently discovered Spectre and Meltdown vulnerabilities.