Threat Database Trojans TROJ_RANSOM.DDR

TROJ_RANSOM.DDR

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 3
First Seen: November 26, 2012
Last Seen: July 3, 2021
OS(es) Affected: Windows

TROJ_RANSOM.DDR is a ransomware Trojan that has caught the attention of PC security researchers because TROJ_RANSOM.DDR makes use of fake digital certificates in its attack. ESG malware analysts have been concerned about the rising number of attacks involving ransomware Trojans. These attacks involve threatening ransom messages that impersonate law enforcement agencies in order to scam inexperienced computer users. TROJ_RANSOM.DDR in particular will display fake messages from the FBI or from many police agencies, depending on the infected computer's geographical location. ESG malware researchers have observed that police ransomware Trojans have started including more advanced features, such as prerecorded threatening audio messages. TROJ_RANSOM.DDR represents one of these advances: the inclusion of fake digital certificates in order to bypass security checks.

TROJ_RANSOM.DDR Uses Fake Digital Certificates to Fool Security Software

ESG security researchers have observed that several versions of this ransomware attack will include the TROJ_RANSOM.DDR fake digital certificates. Since these digital certificates are issued by suspicious sources, it seems that they are mainly designed to allow TROJ_RANSOM.DDR to bypass digital signature checks carried out by security software or components on the victim's computer. Digital signatures are a way for software vendors to help computer users verify that their software is legitimate. However, expired or bogus digital certificates (like TROJ_RANSOM.DDR) can be used to trick computer users and outdated security software. ESG security researchers have observed other malware infections using fake digital certificates, particularly high profile attacks like Flame which used Microsoft digital certificates and some Trojans with expired Adobe digital certificates. TROJ_RANSOM.DDR represents one of the first cases of ransomware Trojans incorporating bogus digital certificates into their attack.

Like most police ransomware Trojans, TROJ_RANSOM.DDR takes over the victim's computer, taking it hostage until the victim pays a ransom. These ransomware attacks use a warning message that tricks the victim into thinking that the message actually comes from their country's police force. These kinds of attacks were first observed in Easter Europe and Russia, dating back to 2005. Since then, ransomware Trojans have quickly spread throughout most of Europe and, since 2011, to parts of North America. TROJ_RANSOM.DDR and its variants will commonly display different messages depending on the infected computer's location (this data can be deduced from the infected computer's IP address). A computer located in the United States will receive a ransom message written in English and claiming to have been sent by the FBI while a computer in the United Kingdom will receive a different message, claiming to have been sent by the UK Police Cyber-Crimes Unit.

Trending

Most Viewed

Loading...