logo

Ransomware Posing As FBI

ID: 37ce183c-0cb1-51cd-bfd6-4d9be5d9d468

STIX ID: report--37ce183c-0cb1-51cd-bfd6-4d9be5d9d468

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

A scareware/lockscreen Trojan delivers fake FBI alerts (displaying alleged pornographic material), disables Task Manager and other recovery tools, installs persistence by hooking Winlogon via a userint.exe process and setting an autostart registry value, stores a malicious index.html under the victim's AppData, and continuously posts victim data to a botnet (observed POSTs every ~5 seconds) with C2 activity tied to Germany; multiple malicious download URLs are listed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.