Ransomware Scammers Get Scammed Themselves By Tor Proxy Hack

Ransomware Scammers Get Scammed Themselves By Tor Proxy Hack

Ransomware is some of the most devious and frustrating malware floating around the internet. These programs lock up your files with encryption and threaten to delete them unless you pay a cryptocurrency ransom. Victims are powerless to thwart the attack, so many just pay up. Now, it’s the scammers who are the victims of a clever ruse by even more devious online criminals. Ransomware payments are being diverted via a man-in-the-middle attack, which is some sort of perverse justice. Still, it won’t do the original ransomware victims any good.

The new attack on scammers was spotted by security firm Proofpoint, which noticed a warning posted to a ransomware payment portal called LockerR. This service runs on the Tor network, a spiderweb of encrypted nodes across the world that can route traffic anonymously and host hidden services. This is where many scammers operate due to the relative safety compared with the open internet. The problem is that most Ransomware victims don’t know how to access Tor. Therefore, scammers direct them to Tor proxies that can load a Tor service in a standard browser. That’s where the scammers are being scammed.

According to the notice posted on LockerR, the onion.top Tor proxy has started redirecting Bitcoin payments from the ransomware makers to a different address. It just replaces the original Bitcoin wallet address with the one owned by the proxy operators. The payment portal encourages victims to use the Tor browser to connect to LockerR directly in order to ensure the Bitcoins make it to the right address. So far, about $22,000 worth of ransomed Bitcoins have been “stolen” from the people who were trying to scam innocent computer users.

Ransomware Scammers Get Scammed Themselves By Tor Proxy Hack

The LockerR payment portal was first spotted in October 2017, and has since become an increasingly popular way for ransomware makers to collect their payments. The supposed deal is that once a user pays the ransom, they will get the encryption key to unlock their files. However, the payment won’t get there if it’s redirected by the Tor proxy and ends up in the wallet of the wrong criminal. Thus, the victim will be out the money and still won’t get their files back. Of course, not all ransomware makers are sufficiently honorable to hold up their end of the bargain in the first place.

The best course of action is to never pay these ransoms and just make sure you’ve got backups of your important files. Let the scammers just scam each other.

Continue reading

Protect Your Online Privacy With the 5 Best VPNs
Protect Your Online Privacy With the 5 Best VPNs

Investing in a VPN is a smart choice right now, but the options are vast. To help narrow things down a bit, we've rounded up five of our very favorite consumer services.

NASA Probe Stows Huge Asteroid Sample for Return to Earth
NASA Probe Stows Huge Asteroid Sample for Return to Earth

Following the recent successful touch and go operation, NASA has reported a sizeable sample of the asteroid has now been locked away in the probe's sample return container.

Voyager 2 Probe Talks to Upgraded NASA Network After 8 Months of Silence
Voyager 2 Probe Talks to Upgraded NASA Network After 8 Months of Silence

NASA just said "hello" to Voyager 2, and the probe said it back.

Scientists 3D Print Microscopic USS Voyager With Its Own Propulsion
Scientists 3D Print Microscopic USS Voyager With Its Own Propulsion

It doesn't have warp engines, but it can get along fine with the help of hydrogen peroxide and platinum.