Ransomware that uses a fake children's charity for phishing

CryptoMix uses information lifted from children's charities to coerce victims into ransom payments

Fake charity message from CryptMix ransomeware

A new strain of ransomware has surfaced that pretends to be working for the good of a children's charity rather than for criminal gain, in an attempt to make handing over cash more palatable for a victim.

The newly discovered CryptoMix has been found masquerading as a Robin Hood-style of ransomware, providing links to a fictitious charity and an offer to put their name with their donation.

Advertisement - Article continues below

First spotted by cyber security firm Covewave, the ransom notes go so far as to include the names, diagnosis, and even pictures of young children that the ransom payments claim to support which, according to Covewave, the information appears to have been lifted from crowdfunding websites.

"In recent cases, Coveware observed ransom notes and communications that referenced a fictitious charity but real children," the company said. "The ransom communications begin with a .txt file that provides email addresses that the victim may use to contact the ransomware distributor."

Covewave have an example of the email exchange hackers use with this scheme. In the correspondence, they claim to work for a fictitious charity and give a description of a child's diagnosis and the funding amount being raised.

Email of a hacker using CryptoMix - courtesy of Covewave

Advertisement - Article continues below

Disturbingly, the email contained an image of what Croewave said appeared to be a 3-year-old girl lifted off a crowdfunding site.

Advertisement - Article continues below

From there, the hacker will direct the victim to view payment information with instructions on a temporary page. This page includes bitcoin wallet payment instructions and more detail on the fake charity.

"We are guessing this tactic is meant to assuage the moral hazard associated with paying a ransom," Covewave explained. "It goes without saying that these cyber criminals did think this through. It is poignantly obvious that the charity is fake, and that the details of the child's case are lifted from other sites."

After paying the ransom, a victim is given more detail about the charity as well as a message suggesting their own name will be used alongside their donation.

CryptoMix has also been identified by Avast as a particularly nasty type of ransomware that can ultimately leaves your files locked even if you pay the ransom.

This strain of ransomware was first spotted in March 2016. The spread of this ransomware could be described as a medium level of prevalence and uses exploit kits as its main delivery method.

Advertisement - Article continues below

"Once CryptoMix infects a machine, it tries to communicate with its command and control server to establish a key to encrypt files. However, if the server is not available or if there is a connection issue, such as a blocked communication by a firewall, the ransomware will encrypt files with one of its fixed keys, or 'offline key'," it said. 

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now



How can you protect your business from crypto-ransomware?

4 Nov 2019
video conferencing

Zoom 5.0 adds 256-bit encryption to address security concerns

23 Apr 2020

WhatsApp flaw leaves users open to 'shoulder surfing' attacks

21 Apr 2020
cyber security

Microsoft AI can detect security flaws with 99% accuracy

20 Apr 2020

Most Popular

Microsoft Windows

Microsoft's latest Windows 10 update is causing yet more issues

26 May 2020

Nokia breaks 5G record with speeds nearing 5Gbps

20 May 2020
Network & Internet

Intel releases Wi-Fi and Bluetooth driver updates for Windows 10

26 May 2020