Stanford student finds glitch in ransomware payment system to save victims $27,000
Full article638 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Sometimes the good guys win.
The hackers behind a nascent strain of ransomware hit a snag this week when a security researcher found a flaw in the payment system and, he says, helped victims save $27,000 in potential losses.
Stanford University student and security researcher Jack Cable got a call Wednesday from a family friend, who is a doctor, asking for help because cybercriminals had locked the doctor’s computer. The doctor was preparing to pay the ransom when Cable began looking at the hackers’ payment system, according to Cable.
The hackers were demanding 0.01 Bitcoin, or roughly $550 at the time, to unlock the doctor’s files. Cable, who served as a cybersecurity adviser to the Department of Homeland Security during the 2020 election, realized that if he changed one letter from lowercase to uppercase in the “transaction ID” the hackers were using to track payments, the system mistook the input for a victim that had already paid and unlocked the files.
The new strain of ransomware, known as QLocker, has flooded the internet in recent days, targeting network storage systems made by Taiwan-based QNAP Systems. The firm confirmed the ransomware attacks on Thursday, saying it was “urgently working on a solution to remove malware from infected devices.”
Cable took to Twitter late Wednesday asking victims of the ransomware to get in touch so he could help recover their data. He said 50 people from various parts of the world messaged him, and that he was able to get their data back using the same glitch in the hackers’ payment scheme. That prevented some $27,000 in potential victim losses.
The ransomware authors have since fixed the glitch, but Cable’s efforts count as a small yet significant win against a broader scourge of ransomware incidents that has affected countless U.S. businesses and government agencies.
“It shows that even though we may think of all attackers as being very sophisticated, the reality is that since this is financially motivated, there’s going to be a range of sophistication levels,” Cable told CyberScoop.
Cybercriminals “looking to make a quick buck” are “unlikely to have a robust security team,” Cable pointed out.
The 21-year-old, who made his name by hacking Pentagon software systems as a teenager to make them more secure, said he would continue to look for weaknesses in attacker infrastructure when he had time.
Ransomware gangs can be “sloppy” in their tradecraft, he added. “To whatever extent we can take advantage of this to reduce the damage can go a long way,” Cable said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/jack-cable-qlocker-ransomware-recovery/