{"id":69452,"date":"2022-11-02T14:12:47","date_gmt":"2022-11-02T12:12:47","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=69452"},"modified":"2025-09-07T20:07:51","modified_gmt":"2025-09-07T17:07:51","slug":"bitcoin-ransomware-attacker-targeted-russians-by-posing-as-a-security-update","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/bitcoin-ransomware-attacker-targeted-russians-by-posing-as-a-security-update\/","title":{"rendered":"Bitcoin ransomware attacker targeted Russians by posing as a security update"},"content":{"rendered":"<p>In late October, Russian-speaking users began receiving malicious spam allegedly from law enforcement and government authorities, containing ransomware. ForkLog reported this, citing experts from Kaspersky Lab.<\/p>\n<p>The company recorded several thousand emails warning users about an uptick in hacker activity and offering them to download a &#8216;special update for security systems&#8217; to protect devices from various online threats. After installing such a solution, the user would supposedly receive a code enabling &#8216;to detect and prevent a cyberattack&#8217;.<\/p>\n<p>In reality, by following the provided link, the user downloaded a ransomware program from the Trojan-Ransom.Python.Agent family. For restoring access to the data, the attackers demanded a ransom of 0.009 BTC.<\/p>\n<p>Kaspersky Lab specialists noted that the mailing was sent using a legitimate service, and the sender&#8217;s address resembled that of an official mailbox of one of the agencies.<\/p>\n<p>As reported by US company SonicWall, in July, amid a drop in Bitcoin&#8217;s price, the number of ransomware attacks <a href=\"https:\/\/u1f987.com\/en\/news\/report-ransomware-attacks-fell-by-23\">substantially decreased<\/a>.<\/p>\n<p>Read ForkLog\u2019s Bitcoin news in our <a href=\"https:\/\/telegram.me\/forklog\" target=\"_blank\" rel=\"nofollow noopener\">Telegram<\/a> \u2014 cryptocurrency news, prices and analysis.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In late October, Russian-speaking users began receiving malicious spam containing ransomware.<\/p>\n","protected":false},"author":1,"featured_media":69453,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,27],"class_list":["post-69452","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-russia"],"aioseo_notices":[],"amp_enabled":true,"views":"15","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/69452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=69452"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/69452\/revisions"}],"predecessor-version":[{"id":69454,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/69452\/revisions\/69454"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/69453"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=69452"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=69452"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=69452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}