Ransomware victims told NSA's Prism program caught them with child pornography

Share this article:

Dealers of ransomware are now attempting to frighten victims into paying up by tricking them into believing they've committed illegal online actions that were uncovered by the National Security Agency's Prism surveillance program.

According to a Sunday post on the "Malware don't need Coffee" blog, the scam functions similarly to other ransomware attacks. If users surf to a compromised site or ad hosting the attack, their screen becomes locked, and a message is displayed. In this case, the messages are customized to appear like they come from the NSA's Prism mass data collection program, whose existence was exposed in documents leaked by whistleblower Edward Snowden.

Victims of the ransomware are told that are under investigation for "illegal content downloading and distribution," specifically child pornography. To avoid prosecution and have their computers unlocked, targets are told they must pay $100 through a Green Dot MoneyPak by purchasing a prepaid card and transferring the value to the fraudsters.

A researcher known as Kafeine who studied the threat believes its purveyors also are responsible for the "Kovter" ransomware, which began spreading earlier this year.

The crooks' command-and-control server is based in Russia, Kafeine said.

Share this article:

Sign up to our newsletters

More in News

In Cisco probe, misuse or compromise spotted on all firms' networks

In Cisco probe, misuse or compromise spotted on ...

Cisco analyzed the business networks of 30 multinational companies last year, and revealed the findings in its 2014 Annual Security Report.

Fareit trojan observed spreading Necurs, Zbot and CryptoLocker

The Necurs and Zbot trojans, as well as CryptoLocker ransomware, has been observed by researchers as being spread through another trojan, known as Fareit.

Post Heartbleed, tech giants join initiative to bolster open source

Post Heartbleed, tech giants join initiative to bolster ...

The newly formed Core Infrastructure Initiative, created to boost under-funded open source projects, will tackle OpenSSL first.