Authored by a Symantec employee
“This operating system has been locked for security reasons.”
Many online users are still being confronted with similar messages to the above thanks to a type of malware called ransomware. The scam works by using malware to disable the victims’ computers until they pay a ransom to restore access. Cybercriminals often use social engineering tricks, such as displaying phony messages purporting to be from local law enforcement, to convince victims to pay up. Messages often include warnings such as, “You have browsed illicit material and must pay a fine.”
A rise in ransomware
Norton by Symantec has witnessed an increase in the amount of professional cyber gangs using ransomware in recent years. This fraudulent activity is designed to take over your computer and blackmail you for cash, and has developed in the following ways:
- After first emerging in Russia and Eastern Europe in 2009, ransomware spread to Western Europe, the U.S. and many other countries, causing high infection rates and a great deal of frustration for consumers.
- Professional cybergangs use intelligent malware which, once on your computer, identifies which country you live in (via your IP address) and presents the message in the local language with a logo of a local public authority.
- The ransomware completely disables the device and is designed so that it seems that the only way to restore functionality is to pay the fine. This raises the chance of the consumer being tricked to pay the ransom.
Different variants of malware are being developed, and within those variants criminals vary the code slightly to help the malware get past security software.
- Ransomware is predominantly found on suspicious websites, and arrives either via a “drive-by download”, stealth download or through a user clicking on an infected advert. Some distribution via email has also been seen.
- Messages are evolving over time. Cybercriminals use different hooks to defraud innocent users (social engineering). Early variants used a locked screen containing pornographic images to shame users into paying the fine, and are now using law enforcement logos.
- Techniques have become more and more sophisticated, with code built into ransomware programs to tailor messages to the right language and local law enforcement logo.
- Even if a person does pay the ransom, the cybercriminals often do not restore functionality. The only reliable way to restore functionality is to remove the malware.
Tips on how to prevent infections by ransomware:
- Have up-to-date security software installed. Remember with thousands of new malware variants running every day, having a set of old virus definitions is almost as bad as having no protection.
- Make sure all the software on your system is up-to-date. This includes the operating system, the browser and all of the plug-ins that a modern browser typically uses. One of the most common infection vectors is a malicious exploit that leverage a software vulnerability. Keeping software up-to-date helps minimize the likelihood that your system has an exposed vulnerability on it.
- Make sure you are leveraging the full set of protection features delivered in your security product. Norton products offer the layers of protection you want.
Symantec Corporation, the world’s leading cyber security company, allows organizations, governments, and people to secure their most important data wherever it lives. More than 50 million people and families rely on Symantec’s Norton and LifeLock comprehensive digital safety platform to help protect their personal information, devices, home networks, and identities.
© 2018 Symantec Corporation. All rights reserved. Symantec, the Symantec Logo, the Checkmark Logo, Norton, Norton by Symantec, LifeLock, and the Lockman Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the United States and other countries. Firefox is a trademark of Mozilla Foundation. Google Chrome is a trademark of Google, Inc. Mac, iPhone