/?pid=15738

Updated:10:42 AM EST Feb 25


this is ggmania.com subsite Is Your Network Infected With Sleeper Ransomware? - TechAmok

Is Your Network Infected With Sleeper Ransomware? - [security]
02:37 PM EDT - May,30 2015 - post a comment

It's called Locker and has been infecting employee's workstations but sat there silently until midnight May 25, 2015 when it woke up. Locker then started to wreak havoc in a massive way. Bleepingcomputer has a support topic that is 14 pages long and they received 100s of emails from consultants all over the world. Based on their experience with cryptoware, they stated this strain has a large "installed" base, which does not bode much good. Topics related to this new strain are suddenly posted on all the major support boards, AV forums, etc. It appears we have a new player in Ransomware City, and this looks like an 800 pound gorilla very similar to CryptoLocker. At the moment, it looks like the infection vector is exploit kits but there are rumors of a compromised MineCraft installer. Here is what it does:

- A series of Windows services are used to install Locker on the computer and encrypt data files.
- During the install process, Locker will check if the computer is virtual machine and terminate if detected.
- Encrypts data files with RSA encryption, and does not change the file extension. After the encryption it deletes your c:\ shadow volume copies and displays its ransom interface.
- If your backups failed and you are forced to pay the ransom, once payment has been confirmed the ransomware will download the private key and automatically decrypt your files.

The files that are encrypted are the following types: .doc, .docx, .xlsx, .ppt, .wmdb, .ai, .jpg, .psd, .nef, .odf, .raw, .pem, .rtf, .raf, .dbf, .header, .wmdb, .odb, .dbf, and again, Locker does not change the file extension so your users will get error messages from their applications that the file is corrupted. As you see on the screenshot, it has a scary message in red at the bottom of the screen stating: "Warning any attempt to remove damage or even investigate the Locker software will lead to immediate destruction of your private key on our server!" This is just to force you into paying, not something to be too worried about.


Add your comment (free registrationrequired)

Short overview of recent news articles

Feb,25 2026 Microsoft Pulls the Plug: Windows Server 2016 and 2016-Era Windows
Feb,25 2026 I Scrapped 13 MACHINES to Prove a Point: STOP BUYING These Brands!
Feb,25 2026 How Stealthy was the 7zip Malware and how to spot it?
Feb,25 2026 Microsoft Drops Fresh Non-Security Boost for Windows 11 24H2 and
Feb,24 2026 Game-Changer: ASML's 1kW EUV Upgrade Promises 50% Chip Production
Feb,24 2026 This Outstanding Cooling Technology Might Have No Future
Feb,24 2026 AMD Strix Halo 395 vs Intel Panther Lake - Real Benchmarks
Feb,24 2026 Anthropic published a blog post saying Claude can modernize COBOL
Feb,24 2026 WhatsApp Goes Beyond 2FA: Extra Password Layer Makes Accounts Nearly
Feb,24 2026 Google Chrome Gets February 23 Security Boost with 3 High Fixes
Feb,23 2026 Stargate Stalls: OpenAI's $500B Dream Hits Roadblocks as $14B 2026
Feb,23 2026 Google Crushes Cyber Threats: Blocks 1.75 Million Bad Apps and Bans
Feb,22 2026 Bitcoin Miner Bitdeer Sells Everything: Treasury Hits Zero in AI
Feb,22 2026 HW News - More Valve RAM Shortages, Tariffs Ruling, AI Causes PS6
Feb,22 2026 Microsoft's Deep Integration of Copilot in Windows 11 Raises
Feb,22 2026 Elon Musk Confirms X Money Now Live in Internal Beta for Employees,
Feb,22 2026 Scream (1996) Flashback Review
Feb,22 2026 PayPal Confirms Major Breach: SSNs, Emails, and More Exposed from
Feb,22 2026 Does Freezing Help Delidding? 9850X3D Delid & Overclocking Test
Feb,22 2026 Microsoft is phasing out the custom primary password feature in its
Feb,21 2026 Everyone is Buying the Wrong Dash Cam! (2026)
Feb,20 2026 Big Brother on Discord: Leaked Code Shows Age Verification Runs You
Feb,19 2026 OpenClaw’s Top Skill is a Malware that Stole SSH Keys and Opened
Feb,19 2026 Google Adds Satellite SOS to its Affordable Pixel Phone
Feb,19 2026 Phison CEO Warns: AI-Driven NAND and DRAM Shortage Could Bankrupt
Feb,19 2026 NVIDIA CEO hypes up GTC 2026, promises to unveil a chip that will
Feb,19 2026 Microsoft is uploading your confidential emails to Copilot for
Feb,18 2026 Anthropic Releases Claude Sonnet 4.6 with Improved Coding, Computer
Feb,17 2026 Apple Eyeing A Partnership With Chinese Memory Makers YMTC And CXMT
Feb,17 2026 This $60,000 TV was IRRESISTIBLE
Feb,17 2026 Keenadu Android Backdoor Infects Firmware, Spreads via Google Play
Feb,17 2026 Discord's ID Check Nightmare Sparks Massive Exodus to TeamSpeak
Feb,17 2026 Amazing Robot Performance at the 2026 Spring Festival Gala
Feb,16 2026 Apple brings video podcasts and other improvements in iOS 26.4 beta
Feb,16 2026 Dutch Defence Secretary Boldly Claims F-35 Software Could Be
Feb,16 2026 Samsung shows off Galaxy S26 Ultra privacy display
Feb,16 2026 60 Million Passwords Exposed? ETH Zurich Shatters 'Unbreakable'
Feb,15 2026 Apple MacBook with iPhone chip launches next month
Feb,15 2026 Discord's Disturbing Ties to Global Surveillance | ID Verification,
Feb,15 2026 20 Mind-Blowing Tech Gadgets You MUST See in 2026!
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs