If you post ads on Craigslist for short term employment, be aware that there’s a new malspam campaign that aims to distribute Sigma ransomware on the computers of unwary users.
By all outward appearances, the emails seem to come from Craigslist in response to ads posted in Craigslist’s “Gigs” section for short term employment. The emails will generally express interest in whatever job the user has posted and include a protected Word or RTF document which recipients will assume are resumes.
If the recipient enters the password to unlock the document, they’ll then be presented with a screen that asks them to enable the content in the document. Unfortunately, this is the step that dooms the user. The file isn’t a resume at all, but merely a delivery vehicle.
As soon as the content is enabled, the ransomware will be installed, the user’s files will be encrypted, and then will “helpfully” post a message explaining that the files have been encrypted, and explaining that to get access to them again, they’ll have to pay a $400 fee, which rises to $800 if the user waits longer than seven days to request the decryption key.
Unfortunately, there’s no known way to decrypt Sigma-encrypted files other than paying the ransom.
This is a new twist on a very old game. Even worse, it’s enjoying a relatively high success rate because people who post ads for short term employment on Craigslist expect to get responses from people they don’t know. They expect that those people will be sending resumes for review.
The “tell” is that when a potential employee sends you a resume, it’s almost certainly not going to be password protected. In this case, your best bet would be to reply to the sending and ask them to send you a non-protected resume if they’re genuinely interested in the job.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
According to a new report published by Spiceworks, nearly 90 percent of businesses will use some type of biometric technology for authentication by the year 2020. In fact, some 62 percent of companies already use biometrics in some form, with another 24 percent stating their intention to do so within the next two years.
A Reddit user named “Noam_ha” recently posted a screenshot displaying a popup message when users open the venerable Windows Media Player (WMP), asking users if they would instead like to open the video file with the company’s more modern Movies and TV app.
The “Spectre” vulnerability that impacts literally every Intel chip made over the last decade keeps finding new ways to make the news. In this instance, researchers at Ohio State University have discovered a new variant of the vulnerability that they have dubbed “SGX Spectre.” To understand how it’s different, a bit of explanation is in order.
If you have a Netflix account and children living at home, there’s a reason to cheer about the company’s most recent announcement. They’re rolling out some robust new parental control features that will allow you to exert much more control over what your children are watching.
By now, you’ve almost certainly heard of the “Spectre” and “Meltdown” security flaws that affect every Intel chip produced in the last decade. Users have been waiting for a fix for both of these since January, when the issues were first discovered.
The CEO of Trustico, a TLS certificate reseller based in the United Kingdom, finds himself at the center of a controversy that raises a number of disturbing questions about browser-trusted security certificates.
It looks like it’s going to be another bad month for Equifax. The company just can’t seem to get out of its own way.
Google has another new product out. A slimmed down, streamlined version of the Android OS called “Go.” Unfortunately, it’s release didn’t gather as much press as you’d expect when a new OS is released. The reason for that is simple. The new, slimmer, sleeker Android Go was designed for low-end phones with limited storage capacity, which don’t typically get much press either.
Do you have a Mi-Cam in your home? Even if you don’t have kids, you may have one. They’re a highly popular, inexpensive means of keeping tabs on the comings and goings inside your home when you’re not around.