LockBit Ransomware Affiliates Trick Users With Malware Disguised As Copyright Claims

Share post:

According to AhnLab researchers, LockBit ransomware affiliates are tricking users into downloading malicious documents via emails disguised as copyright claims.

The emails warned victims of copyright infringement, accusing them of using media files without the license of the author. In the email, recipients were asked to remove the infringing content from their websites or face legal action.

The recipients were asked to download and open the attached files to see the content of the infringement.

The attached document is a password-protected ZIP archive containing a compressed file. In the compressed file is an executable file disguised as a PDF document which in reality is an NSIS installer.

When the victim opens the alleged PDF document, the malware loads and encrypts the device with the LockBit 2.0 ransomware.

Copyright claims are important for publishers of content, but should be flagged if the claims are ambiguous, and ask them to open attachments to display the infringement details.

The tactic of copyright infringement while prominent is not limited to LockBit ransomware attackers alone. LockBit, however, remains the most dominant ransomware group with the most victims. According to NCC Group “Threat Pulse” report for May 2022, LockBit 2.0 accounted for 40% or all (236) ransomware attacks reported in May.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Anthropic Warns: AI “Virtual Employees” Could Pose Security Risks Within a Year

Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as...

Hertz Data Breach Exposes Customer Information via Supply Chain Hack

Hertz has disclosed a data breach resulting from a cyberattack on its vendor, Cleo Communications, which compromised sensitive...

Google’s New Security Feature – Automatic Reboot

Google is introducing a new security feature in its latest Android update that will automatically reboot phones and...

Cybersecurity Firm Prodaft Buys Hacker Forum Accounts to Monitor Cybercriminal Activity

Swiss cybersecurity company Prodaft has initiated a program to purchase verified and aged accounts on hacking forums, aiming...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways