Ransomware Posing As FBI
ID: 37ce183c-0cb1-51cd-bfd6-4d9be5d9d468
STIX ID: report--37ce183c-0cb1-51cd-bfd6-4d9be5d9d468
Feed Name: Zscaler Security Research Blog
A scareware/lockscreen Trojan delivers fake FBI alerts (displaying alleged pornographic material), disables Task Manager and other recovery tools, installs persistence by hooking Winlogon via a userint.exe process and setting an autostart registry value, stores a malicious index.html under the victim's AppData, and continuously posts victim data to a botnet (observed POSTs every ~5 seconds) with C2 activity tied to Germany; multiple malicious download URLs are listed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
