Drop Down MenusCSS Drop Down MenuPure CSS Dropdown Menu

Tuesday 16 May 2017

WHAT IS RANSOMWARE?

Ransomware is a type of a malicious software which is designed to block the access to the victims computer until a money offered by the attacker is paid by the victim.
The ransomware was invented by "Young and Yung" at Columbia University. It is called a cryptoviral extortion. 
In a cryptoviral extortion there are three stages.

  • The attacker generates a private password and the malware. and binds the password with the malware.
  • after the release of the malware , in the victims PC the malware generates a new password called the symmetric key and locks the data of victim using this symmetric key. the symmetric key in the victims PC is also protected by the private key made by the attacker This is called Hybrid encryption. This hybrid encryption results in the generation of  an asymmetric ciphertext and symmetric ciphertext.(Ciphertext is encrypted text. Plain text is what you have before encryption, and ciphertext is the encrypted result). This prevents the victim from recovering his data by using recovery software. whenever the victim opens any file in his PC a message will popup which includes the asymmetric ciphertext and how to pay ransom.
  • For recovering the victims data He need to send the money offered by them by the way they said and the asymmetric ciphertext appeared in the message that poped up. When the attacker receives the money, they will interpret the asymmetric key with the password they have and sends the symmetric key to the victim. the victim regains his data using this symmetric key and the cryptovirology attack completes.
there will be no guarantee that the after payment the victim will get his data back. It depends on the attack.
 2017 made the history of largest ransomware attack. This attack was made by some hacker group called "WannaCRY". They are offering about $300 to $600 dollars for the decryption key. and if the victim didn't pay the money his data will be loossed after a week.
  
There is shame news from WannaCRY that they have only made a total of $60,000 within a month from 150 countries.!!!!
These transactions are made through bitcoin.

WHY BITCOIN?

Bitcoin transaction is the most anonymous mode of transaction . It hides the identity of the attacker or from where and to whom gets the money. The money is transferred in the form of bitcoin. But this type of transactions are public that is the details about the amount and date will be made public but the identity of the peoples making this transaction will be hidden.

There are some websites in deep web that helps in creating ransomwares. 




No comments:

Post a Comment