Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Clustering and Replication
    • Endpoint Management & Virtualization
    • Storage Management
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

The Key(generator) to the SMS Ransomware Threat

Symantec Security Response
May 8th, 2009
Tags: Endpoint Protection (AntiVirus), Malicious Code, Malicious Code, Security, Security Response
Facebook Twitter

Andrea Lelli previously posted an analysis of a threat dubbed Trojan.Ransomlock. This threat was capable of locking out a user’s desktop and would only relinquish its hold when presented with an unlock code. The code, of course, could only be obtained from a premium rate text number. An infected user would be presented with a screen resembling the following on a compromised machine:

When the blog was posted, Symantec also released a tool that could be used to generate the unlock code. As could be expected, soon after this tool was released the attackers updated their code generation algorithm. In response, Symantec has created an online version of the tool, which handles all known code formats:

Symantec will continuously monitor for any new variants, and update the keygen tool as well.

Note: Thanks to Andrea Lelli for his analysis of the threat and John Park for creating the online version of the unlock tool.

0 votes
  • Symantec Security Response's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • Microsoft Patch Tuesday - February 2010
    Robert Keith - February 09, 2010
  • Sale! This Offer is Valid EVERY Week
    Mayur Kulkarni - February 05, 2010
  • SpyEye Bot versus Zeus Bot
    Peter Coogan - February 04, 2010
  • 利用双重漏洞发动攻击的木马Trojan.Hydraq
    Livian Ge - February 03, 2010
  • Phishing Using Pornographic Content as Bait
    Mathew Maniyara - February 03, 2010

Blog Tags

10.x 11.x 9.x and Earlier Brightmail Gateway Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Evolution of Security General Symantec How to IT Risk Management Internet Security Threat Report Malicious Code Mobile & Wireless Online Fraud Platforms & Hardware Restore Security Security Security Risks Spam Vulnerabilities & Exploits Windows
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Newsletter
  • Privacy Policy
  • Symantec.com