Emails sent by cybercriminals using 'GandCrab' have romantic subject lines.
A new round of Phishing emails containing romantic messages has reportedly attempted to quite literally seduce their readers into clicking ransomware-ridden links.
Indeed, the Mimecast Threat Labs Team released a report saying that threat actors behind GandCrab, a ransomware that encrypts its victim’s files, are sending messages with subject lines such as 'This is my love letter to you', 'Wrote my thoughts down about you', 'My letter just for you' and 'Felt in love with you.'
”Felt in Love With You”
The email contains nothing more than an asterisk symbol (*) and an attached zip file. According to the report, each of the zip files is titled “Love_You_2018_” followed by seven or eight random numbers. The unfortunate souls who click the file are then asked if they prefer to see it in English, Chinese, or Korean (an indication that the speakers of these languages are the target victims of the ransomware.)
GandCrab’s victims are then asked to send Bitcoin or DASH cryptocurrency to a wallet address in order to regain access to their files. The victim is told that their ransom will be doubled if it isn’t paid within seven days. Bizarrely, victims who don’t know how to use cryptocurrency can use a sort of live chat window within the ransomware to get help on how to pay the attackers’ demands.
Interestingly, the ransomware can detect Russian victims and will stop the attack on computers who have Russian-configured keyboards. According to Mimecast, “this signals these campaigns are specifically designed to not target Russian users.”
Additionally, GandCrab’s classification as a RaaS means that it’s essentially ransomware for hire: “in a [RaaS] situation, an unprincipled vendor offers hackers and malicious actors a platform tool for the purposes of using ransomware to hold computer files, information or systems hostage,” reads a definition from Techopedia.
The Holidays Are a Busy Time for Cybercriminals
Mimecast’s report also stated that cybercriminals--particularly those that user ransomware--often take advantage of the holidays as a time to pry their way into personal email inboxes.
The holiday season also “[offers] the opportunity for threat actors to harvest a vast amount of information and data that is input into online shopping websites by coming up with fake websites and fake customer surveys that promise to deliver anything from fake vouchers to ‘great deals’ to the victim,” the report said.
Mimecast identified several different kinds of emails and websites in addition to the fake romantic messages, including fake e-greetings, fake online customers surveys, emails offering fake gifts and services, malicious dating apps, and non-malicious dating apps and websites that had been hacked.
A new round of Phishing emails containing romantic messages has reportedly attempted to quite literally seduce their readers into clicking ransomware-ridden links.
Indeed, the Mimecast Threat Labs Team released a report saying that threat actors behind GandCrab, a ransomware that encrypts its victim’s files, are sending messages with subject lines such as 'This is my love letter to you', 'Wrote my thoughts down about you', 'My letter just for you' and 'Felt in love with you.'
”Felt in Love With You”
The email contains nothing more than an asterisk symbol (*) and an attached zip file. According to the report, each of the zip files is titled “Love_You_2018_” followed by seven or eight random numbers. The unfortunate souls who click the file are then asked if they prefer to see it in English, Chinese, or Korean (an indication that the speakers of these languages are the target victims of the ransomware.)
GandCrab’s victims are then asked to send Bitcoin or DASH cryptocurrency to a wallet address in order to regain access to their files. The victim is told that their ransom will be doubled if it isn’t paid within seven days. Bizarrely, victims who don’t know how to use cryptocurrency can use a sort of live chat window within the ransomware to get help on how to pay the attackers’ demands.
Interestingly, the ransomware can detect Russian victims and will stop the attack on computers who have Russian-configured keyboards. According to Mimecast, “this signals these campaigns are specifically designed to not target Russian users.”
Additionally, GandCrab’s classification as a RaaS means that it’s essentially ransomware for hire: “in a [RaaS] situation, an unprincipled vendor offers hackers and malicious actors a platform tool for the purposes of using ransomware to hold computer files, information or systems hostage,” reads a definition from Techopedia.
The Holidays Are a Busy Time for Cybercriminals
Mimecast’s report also stated that cybercriminals--particularly those that user ransomware--often take advantage of the holidays as a time to pry their way into personal email inboxes.
The holiday season also “[offers] the opportunity for threat actors to harvest a vast amount of information and data that is input into online shopping websites by coming up with fake websites and fake customer surveys that promise to deliver anything from fake vouchers to ‘great deals’ to the victim,” the report said.
Mimecast identified several different kinds of emails and websites in addition to the fake romantic messages, including fake e-greetings, fake online customers surveys, emails offering fake gifts and services, malicious dating apps, and non-malicious dating apps and websites that had been hacked.
Rachel is a self-taught crypto geek and a passionate writer. She believes in the power that the written word has to educate, connect and empower individuals to make positive and powerful financial choices. She is the Podcast Host and a Cryptocurrency Editor at Finance Magnates.
FM's Editor-in-Chief Yam Yehoshua on how the newsroom evaluates stories.
FM's Editor-in-Chief Yam Yehoshua on how the newsroom evaluates stories.
FM's Editor-in-Chief Yam Yehoshua on how the newsroom evaluates stories.
FM's Editor-in-Chief Yam Yehoshua on how the newsroom evaluates stories.
Matthew Smith, Group CEO at EC Markets, speaking at FMLS:24
Matthew Smith, Group CEO at EC Markets, speaking at FMLS:24
Matthew Smith, Group CEO at EC Markets, speaking at FMLS:24
Matthew Smith, Group CEO at EC Markets, speaking at FMLS:24
Finance Magnates Annual Awards 2024 | FM Awards 2024 Highlights
Finance Magnates Annual Awards 2024 | FM Awards 2024 Highlights
🎥Catch the best moments from the Finance Magnates Annual Awards Gala Dinner!
An evening where top names in finance came together to celebrate achievements, enjoy live music, and connect over a memorable dinner. Watch the highlights and feel the energy of our first gala in Cyprus!
Congratulations to all the winners for their dedication to excellence and leadership in the financial industry, including XM, Trading PRO, FP Markets, Deriv, FxPro, LATAM, Headway, ATFX, FBS, AMEGA, EC Markets, Axi
For more information about the 1st Finance Magnates Annual Awards, visit https://bit.ly/3Zb7wNz
#FinanceMagnatesGala #IndustryExcellence #GalaHighlights #FinanceMagnatesAnnualAwards #FinanceMagnatesAwards #CelebratingSuccess #FinanceCommunity
🎥Catch the best moments from the Finance Magnates Annual Awards Gala Dinner!
An evening where top names in finance came together to celebrate achievements, enjoy live music, and connect over a memorable dinner. Watch the highlights and feel the energy of our first gala in Cyprus!
Congratulations to all the winners for their dedication to excellence and leadership in the financial industry, including XM, Trading PRO, FP Markets, Deriv, FxPro, LATAM, Headway, ATFX, FBS, AMEGA, EC Markets, Axi
For more information about the 1st Finance Magnates Annual Awards, visit https://bit.ly/3Zb7wNz
#FinanceMagnatesGala #IndustryExcellence #GalaHighlights #FinanceMagnatesAnnualAwards #FinanceMagnatesAwards #CelebratingSuccess #FinanceCommunity
FMLS:24 | Shaping the Next Era of Financial Evolution
FMLS:24 | Shaping the Next Era of Financial Evolution
Welcome to FMLS:24 – the premier event where influential brands and leaders in trading, payments, fintech, and digital assets come together!
Join over 2,500 industry professionals, engage with 150+ expert speakers, and discover endless opportunities with 70+ top exhibitors. FMLS:24 is where senior executives and decision-makers gather to close deals, forge new partnerships, and strengthen connections with long-term clients.
Whether you’re in finance, technology, or payments, this summit is your gateway to future growth, meaningful collaborations, and industry-leading insights.
👉 Don't miss out – secure your ticket now at https://events.financemagnates.com/ZQEYy0?utm_source=youtube&utm_campaign=fmls24-awareness&utm_medium=video&RefId=MLS%3A24+Video+Promo
#fmls #fmls24 #fmevents #financemagnates #forex #payments #crypto #events #london #fintech #ai #generativeai #technology #onlinetrading #forex #investing #investors #tech
📣 Stay updated with the latest in finance and trading!
Follow FMevents across our social media platforms for news, insights, and event updates. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/showcase/financemagnates-events/
👍 Facebook: https://www.facebook.com/FinanceMagnatesEvents
📸 Instagram: https://www.instagram.com/fmevents_official
🐦 Twitter: https://twitter.com/F_M_events
🎥 TikTok: https://www.tiktok.com/@fmevents_official
▶️ YouTube: https://www.youtube.com/@FinanceMagnates_official
Don't miss out on our latest videos, interviews, and event coverage. Subscribe to our YouTube channel for more!
Welcome to FMLS:24 – the premier event where influential brands and leaders in trading, payments, fintech, and digital assets come together!
Join over 2,500 industry professionals, engage with 150+ expert speakers, and discover endless opportunities with 70+ top exhibitors. FMLS:24 is where senior executives and decision-makers gather to close deals, forge new partnerships, and strengthen connections with long-term clients.
Whether you’re in finance, technology, or payments, this summit is your gateway to future growth, meaningful collaborations, and industry-leading insights.
👉 Don't miss out – secure your ticket now at https://events.financemagnates.com/ZQEYy0?utm_source=youtube&utm_campaign=fmls24-awareness&utm_medium=video&RefId=MLS%3A24+Video+Promo
#fmls #fmls24 #fmevents #financemagnates #forex #payments #crypto #events #london #fintech #ai #generativeai #technology #onlinetrading #forex #investing #investors #tech
📣 Stay updated with the latest in finance and trading!
Follow FMevents across our social media platforms for news, insights, and event updates. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/showcase/financemagnates-events/
👍 Facebook: https://www.facebook.com/FinanceMagnatesEvents
📸 Instagram: https://www.instagram.com/fmevents_official
🐦 Twitter: https://twitter.com/F_M_events
🎥 TikTok: https://www.tiktok.com/@fmevents_official
▶️ YouTube: https://www.youtube.com/@FinanceMagnates_official
Don't miss out on our latest videos, interviews, and event coverage. Subscribe to our YouTube channel for more!