| 14 |
| Apr |
Article from Rik Ferguson
Filed under: Family Safety,Opinion,Social Engineering,Underground Economy,malware | RSS 2.0 | TB | Tags: cybercrime, data loss, malicious code, malware | 16 Comments
UPDATE: – Due to a little confusion in the BBC article about this blog entry, I am mistakenly attributed in many stories as saying that this malware is linked with the name Shoen Overns which in turn is linked to ZeuS and Koobface campaigns. This is not the case. When talking to the BBC I was pointing out the parallels in the modus operandi of this threat and a separate recent extortion threat in Europe detailed by Dancho Danchev here. The two are not at all linked to the best of my knowledge.
A colleague of mine, Noriaki Hayashi, brought my attention to an interesting Trojan that has begun circulating in Japan. The malware is aimed at extorting money from its embarrassed victims and here’s how it works.
The victims are initially hooked when they download what they believe to be illegal copies of games from file sharing networks, in most cases the malware is masquerading as illegal copies of ”over 18″ hentai-themed games such as the below
Once the installer is launched it brings up a form requiring the user to enter personal information including their full name, date of birth, game password, email address, postal address, gender, annual income, company name and telephone number along with a few other things for good measure.
While all this is going on, the malware is also automatically collecting details about the victim’s computer including user account, domain and computer name, OS version information, clipboard content, file use history and Internet Explorer favourites. It also grabs a few screen shots just in case they don’t already have enough dirt.
All of this information is then subsequently published on a publicly available website and it’s not long before the victim receives a “helpful” email.
The email comes from a company calling themselves “Romancing Inc” (who coincidentally also own the domain where the stolen information has been published) and they alert the unfortunate mark to the predicament offering to resolve the “copyright infringement” and get the information removed… For a fee.
It may well be that the attackers have a second trap up their kimono as well, the installer also plants a few mp3 files onto the victim machine called Buck Duck, Chukar and Quail. These mp3 files are up for sale at a very high price on a separate website (58 million Yen is about 402 thousand pounds)
Could it be that once a victim has shown themselves to be extortion-friendly they will get hit with yet another “copyright infringement” notice from Romancing Inc? Japanese copyright law was strengthened this year largely in an attempt to address the problem of illegal downloading
This is certainly another illustration of why, in the long run, you may well be better off paying up front for your downloads and steering clear of file-sharing networks.
| Rik Ferguson: Thursday, 15. April 2010 um 10:03 am |
|
|
I’d prefer to call it realistic… |
|
| Netaji: Thursday, 15. April 2010 um 7:14 pm |
|
|
‘you may well be better off paying up front for your downloads and steering clear of file-sharing networks.’ OR You could switch to a mac OS. |
|
| lolnonymous: Thursday, 15. April 2010 um 11:09 pm |
|
|
A mac OS so you can’t run any useful at all? Good plan, bro. |
|
| someone: Friday, 16. April 2010 um 1:21 pm |
|
|
All of this information is then subsequently published on a publicly available website url plz |
|
| Rik Ferguson: Friday, 16. April 2010 um 2:03 pm |
|
|
It was all published at warezer.net but that has now been taken down |
|
| noncompoop: Friday, 16. April 2010 um 7:27 pm |
|
|
LOL, what a bunch of maroons… tricked, clicked and dicked! lol amateurs on line! |
|
| Jogos hentai contaminam PCs no Japão « Alify-Z WebBlog Portal: Saturday, 17. April 2010 um 1:54 am |
|
|
[...] chamada Romancing Inc, que oferece a resolução para o suposto problema de copyright”, afirma Rik Ferguson, analista da Trend Micro. CategoriasNotícias Tags:notícia Comentários (0) Trackbacks [...] |
|
| Virus pornophobe et hacker en culotte courte | Les Concepts: Sunday, 18. April 2010 um 5:17 pm |
|
|
[...] via linformaticien.com / technotes (blog.lefigaro.fr) / countermeasures.trendmicro.eu [...] |
|
| Le virus qui publie l’historique porno de ses victimes | Actualité Internationale: Monday, 19. April 2010 um 11:31 am |
|
|
[...] Tout cela pour faire bonne mesure pendant que le virus opère et récupère de nombreuses données sur le PC: nom de l’ordinateur, numéro de version d’Internet Explorer, le contenu du presse-papiers et bien sûr l’historique d’Internet Explorer qui permettra par la suite de faire chanter les victimes. Histoire que l’internaute soit assuré que c’est bien son ordi qui été piraté, le virus prend aussi quelques captures d’écran, explique sur son blog l’éditeur de logiciel de sécurité Trend Micro qui révèle l’affaire. [...] |
|
| un virus rançonne des amateurs: Wednesday, 21. April 2010 um 12:40 am |
|
|
[...] la société de sécurité informatique Trend Micro qui a repéré cette menace. Celle-ci sévit sur les réseaux peer to peer [...] |
|
| InfoWester Notícias » Malware chantageia usuários que baixam conteúdo adulto: Thursday, 22. April 2010 um 11:55 am |
|
|
[...] Trend Micro, BBC [...] |
|
| Malware chantageia usuários que baixam conteúdo adulto « Vitrinando: Thursday, 22. April 2010 um 6:20 pm |
|
|
[...] Trend Micro, BBC [...] |
|
| Rocker: Thursday, 29. April 2010 um 4:08 pm |
|
|
So how does the European version differ? Does it still only affect those using a file sharing website? |
|
| Malware threatens victims using copyright laws « The FORWARD project blog: Monday, 31. May 2010 um 12:24 am |
|
|
[...] and offers to resolve it for a 1500 yen (~16$) fee. Also, as noted in Trend Micro’s Blog article, it also downloads ,in victim’s computer, 3 copyrighted MP3 files, possibly to extend the [...] |
|



Thursday, 15. April 2010 um 9:19 am
Nice article if it wasn’t for the moralistic bottom line.