“In recent cases, they observed ransom notes and communications that referenced a fictitious charity but real children,” the company said. “The ransom communications begin with a .txt file that provides email addresses that the victim may use to contact the ransomware distributor.”
Coveware have an example of the email exchange hackers use with this scheme. In the correspondence, they claim to work for a fictitious charity and give a description of a child’s diagnosis and the funding amount being raised.
Email of a hacker using CryptoMix – courtesy of Coveware
Disturbingly, the email contained an image of what appeared to be a 3-year-old girl lifted off a crowdfunding site.
From there, the hacker will direct the victim to view payment information with instructions on a temporary page. This page includes bitcoin wallet payment instructions and more detail on the fake charity.
“We are guessing this tactic is meant to assuage the moral hazard associated with paying a ransom,” Coveware explained. “It goes without saying that these cyber criminals did think this through. It is poignantly obvious that the charity is fake, and that the details of the child’s case are lifted from other sites.”
After paying the ransom, a victim is given more detail about the charity as well as a message suggesting their own name will be used alongside their donation.
CryptoMix has also been identified by Avast as a particularly nasty type of ransomware that can ultimately leaves your files locked even if you pay the ransom.
This strain of ransomware was first spotted in March 2016. The spread of this ransomware could be described as a medium level of prevalence and uses exploit kits as its main delivery method.
“Once CryptoMix infects a machine, it tries to communicate with its command and control server to establish a key to encrypt files. However, if the server is not available or if there is a connection issue, such as a blocked communication by a firewall, the ransomware will encrypt files with one of its fixed keys, or ‘offline key’,” it said.