logo

Malware dev lures child exploiters into honeytrap to extort them

ID: 6dac6e59-a49a-5095-816c-db9fb3d8b91a

STIX ID: report--6dac6e59-a49a-5095-816c-db9fb3d8b91a

Feed Name: Bleeping Computer

Threat Score
35/100

Date Published: 2024-04-21

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

BleepingComputer analyzed a recent campaign distributing a Windows malware named CryptVPN (PedoRansom) via a fake UsenetClub site: a downloaded ZIP contains a PowerShell shortcut that fetches and runs a UPX-packed executable saved as C:\Windows\Tasks.exe. Once executed the binary changes the desktop wallpaper to an extortion demand and drops README.TXT demanding $500 to a specified Bitcoin address (bc1q4zfspf0s2gfmuu8h5k0679sxgxjkd7aj5e6qyl); the unpacked binary contains a PDB path identifying it as PedoRansom and reported payments to the address are minimal, indicating limited impact so far.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.