funsec mailing list archives

Re: Ransomeware


From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Sun, 19 Mar 2006 10:05:45 +1200

Gadi Evron to me:

Google for something akin to:

   Popp "AIDS Trojan"

and see that that we've been facing this kind of "attack" for more than 
15 years.

How little folk learn...

This was a buzzword induced frenzy last year around September.  ...

I seem to recall it was first (?) used (though maybe it didn't "stick" 
then) in May 2005 around the GpCode/PGPcoder incident.

...  Shouldn't 
new buzzwords be new?

At least tautologically, I guess...    8-)

I was commenting on the _lack of_ newness.

And it's hardly like there really is a new trend here -- three or four 
incidents in 14-15 months is hardly deserving of a new buzzword or 
terminology.  Afterall, Trojans are arbitrary code and that is all this 
really is, plus we have seen a few non-wild viruses with "data 
encryption apparently aimed at extortion" payloads after Popp and 
before GpCode too.

http://blogs.securiteam.com/index.php/archives/94

I think we're mainly in agreement here...


Regards,

Nick FitzGerald

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: