• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Scammers Stole money From Ransomware Virus Attackers

March 10, 2018Simeon Georgiev

Hackers and cyber attackers have always been a problem for the online community, since the inception of the internet. Most hackers attack a website with the intent to cause damage or acquire sensitive data and then use this information to demand money from their targets.

Bitcoin and similar cryptocurrencies are particularly targeted by hackers. This is because these payment methods allow complete anonymity to users. If hackers can crack someone’s online digital wallet, they would be able to transfer money to their own wallet and sell it later on a virtual currency exchange. Even if the victim can somehow find out which IP address was used to hack their system, they cannot do anything to get the coins back.

Ransomware Virus

This virus attack has the potential to deactivate a company’s database and completely freeze their processes.  It can be sent through a phishing email. When the user clicks on the link, it activates a macro on the target computer which encrypts all the data on the system. Unless the user has backup, they become unable to access any of their files or documents.

The hacker then demands money before they would give the user the keys to decrypt and access the files. As Bitcoin offers complete anonymity, hackers often prefer taking payments in cryptocurrencies such as Bitcoin or Ethereum.

Hackers Got Scammed

Recently, hackers that used ransomware viruses to target businesses were tricked by other crooks who used their own programs to redirect payments from the victims to their own accounts.

While this may seem like justice was served, the ultimate losers were victims of the original hack. They did not receive the decryption keys from hackers as hackers never received the ransom payments.

Cyber attackers trust and use VPN platforms like the TOR project. These platforms allow complete anonymity for users allowing hackers to appear like normal traffic. All websites on the TOR network have the extension .onion. which is run by the Onion.top proxy.

How the Attack Took Place

It appears that while the hackers were connected to hacked systems, they sent their victims Bitcoin wallet addresses to deposit the ransom money. At the same time, operators of the Onion.top proxy scanned their portals in search of Bitcoin wallet addresses and then replaced these addresses with their own wallet address.

When the victims deposited money into the wallet addresses provided by the ransomware attackers, it went into the wallet of the .onion operators instead of the hackers.

It appears that wallet addresses were switched on several ransomware payment sites that are connected to malware strains like GlobeImposter and LockeR. The owners of these services were able to steal at least 2.2 Bitcoins. This would be something close to $20,000 given the current value of Bitcoin.

Perhaps the most interesting part about this whole event is that it was the hackers who announced what was going on. Anonymous posters on Ransomware message boards cautioned other hackers not to use the services of Onion.top proxy.

Ransom hackers have now started taking steps to ensure that they get money into their own wallets. For example, they have now started breaking their wallet addresses with tags to make it more difficult for site operators to find their wallets.

The individuals who were hacked were the only real victims in this whole affair as they did not receive the decryption keys and lost money as well.

For assistance with file recovery and ransomware removal, please contact MonsterCloud – cyber security experts for a professional ransomware removal.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Healthcare Ransomware Attack Affects 6.5K at AL Practice Next post Bitcoin Fluctuations Are Driving Ransom Hackers Away From Demanding Bitcoin

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Ransomware: 4 Types of the Latest Trend in Cybercrimes

February 1, 2018Simeon Georgiev
Ransomware: 4 Types of the Latest Trend in Cybercrimes

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.