Skip to main content

Koler ‘police’ mobile ransomware now targets PCs as well as Android

28 July 2014

UK has second highest number of Koler victims

The ransomware displays customised messages to victims from 30 countries

Kaspersky Lab has detected a hidden part of the malicious campaign which introduced Koler ‘police’ mobile ransomware for Android devices to the world in April 2014. This part includes some browser-based ransomware and an exploit kit. Since July 23 the mobile component of the campaign has been disrupted, as the command and control server started sending ‘Uninstall’ commands to mobile victims, effectively deleting the malicious application. However, the rest of the malicious components for PC users – including the exploit kit – are still active. Kaspersky Lab is keeping an eye on the malware, which was first described by a security researcher named Kaffeine*.

Those behind the attacks employed an unusual scheme to scan victims’ systems and offer customised ransomware depending on location and device type – mobile or PC. The redirection infrastructure is the next step, after a victim visits any of at least 48 malicious pornographic websites used by Koler’s operators. The use of a pornographic network for this ransomware is no coincidence: victims are more likely to feel guilty about browsing such content and pay the alleged fine from the ‘authorities’.

These pornographic sites redirect users to the central hub that uses the Keitaro Traffic Distribution System (TDS) to redirect users again. Depending on a number of conditions, this second redirection can lead to three different malicious scenarios:

 

  • Installation of the Koler mobile ransomware. In case of mobile engagement the website automatically redirects the user to the malicious application. The user still has to confirm the download and installation of the app – called animalporn.apk – which is actually Koler ransomware. It blocks the screen of an infected device and requests a ransom of between $100 and $300 in order to unlock it. The malware displays a localised message from the ‘police’, making it more realistic.
  • Redirection to any of the browser ransomware websites. A special controller checks whether (i) the user agent is from one of 30 affected countries, (ii) the user isn’t an Android user, and (iii) the request contains no Internet Explorer user agent. If it’s yes to all three, the user sees a blocking screen identical to the one used for mobile devices. There is no infection in this case, just a pop-up showing a blocking template. However, the user can easily avoid the block with a simple alt+F4 combination.
  • Redirection to a website containing the Angler Exploit Kit. If the user uses Internet Explorer, then the redirection infrastructure used in this campaign sends the user to sites hosting the Angler Exploit Kit, which has exploits for Silverlight, Adobe Flash and Java. During Kaspersky Lab’s analysis, the exploit code was fully functional; however, it didn’t deliver any payload, but this may change in the nearest future.

Commenting on the new findings on Koler, Vicente Diaz, Principal Security Researcher at Kaspersky Lab, said: “Of most interest is the distribution network used in the campaign. Dozens of automatically generated websites redirect traffic to a central hub using a traffic distribution system where users are redirected again. We believe this infrastructure demonstrates just how well organised and dangerous this campaign is. The attackers can quickly create similar infrastructure thanks to full automation, changing the payload or targeting different users. The attackers have also thought up a number of ways of monetising their campaign income in a truly multi-device scheme.”

Mobile payload numbers

Among almost 200,000 visitors to the mobile infection domain since the beginning of the campaign, the majority are based in the USA (80 per cent – 146,650), followed by the UK (13,692), Australia (6,223), Canada (5,573), Saudi Arabia (1,975) and Germany (1,278).

Kaspersky Lab has shared its findings with both Europol and Interpol, and is currently cooperating with law enforcement agencies to explore possibilities for shutting down the infrastructure.

Tips for users – how to stay secure:

  • Remember that you will never get official ‘ransom’ messages from the police, so never pay them;
  • Don’t install any app you find while browsing;
  • Don’t visit websites you don’t trust;
  • Use a reliable antivirus solution.

Kaspersky Lab detects this ransomware as Trojan.AndroidOS.Koler.a.

The full report is available at securelist.com
Cyberthreat real-time map

*http://malware.dontneedcoffee.com/2014/05/police-locker-available-for-your.html

Koler ‘police’ mobile ransomware now targets PCs as well as Android

UK has second highest number of Koler victims
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help over 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Related Articles Press Releases