Ransomware Scammers Get Scammed Themselves By Tor Proxy Hack

Ransomware Scammers Get Scammed Themselves By Tor Proxy Hack

Ransomware is some of the most devious and frustrating malware floating around the internet. These programs lock up your files with encryption and threaten to delete them unless you pay a cryptocurrency ransom. Victims are powerless to thwart the attack, so many just pay up. Now, it’s the scammers who are the victims of a clever ruse by even more devious online criminals. Ransomware payments are being diverted via a man-in-the-middle attack, which is some sort of perverse justice. Still, it won’t do the original ransomware victims any good.

The new attack on scammers was spotted by security firm Proofpoint, which noticed a warning posted to a ransomware payment portal called LockerR. This service runs on the Tor network, a spiderweb of encrypted nodes across the world that can route traffic anonymously and host hidden services. This is where many scammers operate due to the relative safety compared with the open internet. The problem is that most Ransomware victims don’t know how to access Tor. Therefore, scammers direct them to Tor proxies that can load a Tor service in a standard browser. That’s where the scammers are being scammed.

According to the notice posted on LockerR, the onion.top Tor proxy has started redirecting Bitcoin payments from the ransomware makers to a different address. It just replaces the original Bitcoin wallet address with the one owned by the proxy operators. The payment portal encourages victims to use the Tor browser to connect to LockerR directly in order to ensure the Bitcoins make it to the right address. So far, about $22,000 worth of ransomed Bitcoins have been “stolen” from the people who were trying to scam innocent computer users.

Ransomware Scammers Get Scammed Themselves By Tor Proxy Hack

The LockerR payment portal was first spotted in October 2017, and has since become an increasingly popular way for ransomware makers to collect their payments. The supposed deal is that once a user pays the ransom, they will get the encryption key to unlock their files. However, the payment won’t get there if it’s redirected by the Tor proxy and ends up in the wallet of the wrong criminal. Thus, the victim will be out the money and still won’t get their files back. Of course, not all ransomware makers are sufficiently honorable to hold up their end of the bargain in the first place.

The best course of action is to never pay these ransoms and just make sure you’ve got backups of your important files. Let the scammers just scam each other.

Continue reading

Newegg Changes Return Policy to Combat Scammers, Harm Customers
Newegg Changes Return Policy to Combat Scammers, Harm Customers

Newegg is trying to crack down on scammers, but it's catching regular users in the same net.

Scammers Use YouTube Copyright Strikes in Extortion Scheme
Scammers Use YouTube Copyright Strikes in Extortion Scheme

Some particularly unscrupulous people have realized that Google's YouTube copyright strike system makes a good extortion tool, so they're using it to threaten YouTubers.

Scammers Using Firefox Bug to Lock Down Browsers
Scammers Using Firefox Bug to Lock Down Browsers

Mozilla is reportedly working on a fix for this issue, but users with less technical knowledge may be unable to get rid of the locked page even after restarting the browser.

Tesla Cybertruck Took in $20M Over the Weekend. How’d the Windows Scammers Do?
Tesla Cybertruck Took in $20M Over the Weekend. How’d the Windows Scammers Do?

The guy just pulled in 200,000 pre-orders in 72 hours. So did the critics lay off Elon Musk? Not a chance. Many wonder if Cybertruck will ship looking like this, or there'll be a "real" design later.