Categories: SecurityWorkspace

Super-Rare Ransomware Breaches Boot Record

A very rare piece of ransomware that stops machines from loading up has been spotted by security giant Trend Micro.

Typically, ransomware encrypts files or restricts user access to the infected system, but the TROJ_RANSOM.AQB variant infects the Master Boot Record (MBR) of computers. The ransomware copies the original MBR and overwrites it with its own malicious code.

A user running an infected machine would be barred from entering their operating system. Instead, when their system is booting up, they will be asked to pay money in order to get a password to unlock the computer. They are asked to pay 920 Ukranian hryvnia (£72.32).

Hidden malware?

As for how rare this kind of malicious kit is, this piece of ransomware is one of a handful that have ever been seen.

“As of now, this is the only sample I have encountered. The ransomware that we usually get just disables some Windows Utilities or encrypt files but not as deep as this one. We currently have not seen any other variant using different language,” Rik Ferguson, Trend Micro’s director of director of security research and communication, told TechWeekEurope.

“Based on our analysis, after entering the unlock code, the OS loading will resume. Rescanning the MBR and restarting the system shows that the infected MBR has been removed.”

What’s more, Trend analysis has indicated the ransomware may be doing other nasty things.

“This malware may have other component malware. Also, it is possible that a component malware may execute this infector and may cause reinfection,” Ferguson said.

This is not the first piece of MBR-infecting ransomware ever seen. Back in November 2010, Kaspersky spotted ransomware doing the same, demanding a ransom to retrieve a password and restore the original MBR.

The infamous Cutwail botnet has been one of the biggest pushers of ransomware.

How well do you know security? Test yourself with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Virgin Media O2 To Invest £700m To ‘Transform’ 4G, 5G Network

Virgin Media O2 confirms it will invest £2m a day for new mobile masts, small…

2 days ago

Tesla Cybertruck Deliveries On Hold Due To Faulty Side Trim

Deliveries of Telsa's 'bulletproof' Cybertruck are reportedly on hold, amid user complaints side trims are…

2 days ago

Apple Plots Live Translation Option For AirPods – Report

New feature reportedly being developed by Apple for iOS 19, that will allow AirPods to…

2 days ago

Binance Token Rises After Trump Stake Report

Binance BNB token rises after WSJ report the Trump family is in talks to secure…

3 days ago

iRobot Admits ‘Substantial Doubt’ Over Continued Operation

After failed Amazon deal, iRobot warns there is “substantial doubt about the Company's ability to…

3 days ago

Meta’s Community Notes To Use X’s Algorithm

Community Notes testing across Facebook, Instagram and Threads to begin next week in US, using…

3 days ago