Focus on trojans – holding data to ransom

David Emm · Network Security · 2006

The ancient Greeks have a lot to answer for. Three thousand years after the wooden horse idea entered their heads (and Troy), three quarters of malware threats today are trojan programs based on the same idea. Cyber-blackmail is now one of the key criminal motives. The first three months of 2006 saw a significant increase in the incidence of cyber-blackmail whereby virus writers use malicious programs such as trojans to penetrate victims' machines and encrypt their data. The victim is then informed that the data will only be decrypted once payment has been received – usually between $50 and $2,500. The most striking examples of this type of cyber-blackmail, carried out in the second half of 2005, are the trojans, GpCode and Krotten. The latest variant of GpCode which appeared in January 2006 differed radically from its predecessors in that it used one of the best known and most secure public encryption algorithms, RSA. It has raised the game, as we hear from a malware tracking specialist. Currently 75% of malware threats are trojans. Typically, trojans are dropped onto a victim machine by a virus or worm, or downloaded from a remote site. Trojans don't have their own on-board replication capability. For this reason, they are sometimes mistakenly perceived as being less dangerous than viruses or worms. Not so.

Read the paper · More papers on PaperTik