• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Geek's Advice

IT News, Software Reviews, How To's & Computer Help

  • News
  • Reviews
  • Removal guides
  • Fix
  • Tutorials
  • Forum
  • ASK A GEEK

Fake Windows 10 Updates Infect Computers with Magniber Ransomware

May 2, 2022 By Norbert Webb Leave a Comment

Threat actors use Windows updates as a bait to spread Magniber ransomware

Contents

  • Threat actors use Windows updates as a bait to spread Magniber ransomware
  • Magniber ransomware overview
    • Contents of the ransom note
    • The payment site

Magniber ransomware operators have taken a new approach to distribute the virus. A recent investigation shows that cybercriminals are using fake Windows 10 cumulative or security updates as a bait to trick unsuspecting victims into downloading the ransomware payload. According to reports, these deceptive downloads are promoted via websites offering cracked software versions (warez and crack sites).

The first samples of this malware in VirusTotal and App.Any.Run submissions were spotted on February 22th, 2022 and it is believed to be the starting day of this ransomware campaign. A more significant number of samples were also spotted in the beginning of April.

Some of the most common names used to disguise the deceptive files with the malware inside of them were:

  • Win10.0_System_Upgrade_Software.msi;
  • Security_Upgrade_Software_Win10.0.msi;
  • System.Upgrade.Win10.0-KB47287134.msi;
  • System.Upgrade.Win10.0-KB82260712.msi;
  • System.Upgrade.Win10.0-KB18062410.msi;
  • Win10.Update-KB8723467.msi;
  • System.Upgrade.Win10.0-KB66846525.msi.

In order to avoid getting infected, computer users are advised to only download updates from legitimate websites. When it comes to Windows updates, it is best to check for them via your computer’s Update & Security settings or the official Microsoft.com website only.

Magniber ransomware virus is being distributed via fake Windows 10 update installers

Magniber ransomware overview

After landing on the victim’s computer, Magniber ransomware begins its operation by deleting Volume Shadow Copies. Next, it encrypts all files stored in each folder except those essential for the functionality of the operating system. The virus also marks each encrypted file with additional extension. Some samples of analyzed malware variants used .gtearevf, .vpkrzajx or .nstqjdgxj extension to mark infected files. In other words, the ransomware seems to be using a randomly generated 8 or 9 character string as a new extension for affected data.

Contents of the ransom note

The ransomware creates and saves a copy of a ransom note dubbed README.html in each affected folder. This file opens via computer’s default web browser and displays a message from the ransomware operators. The first line suggests that all of victim’s documents, photos, databases and other important files have been encrypted.

The document reassures the computer user that files are only modified and not “damaged.” However, the note instructs that in order to reverse the modification inflicted on all files, the computer user has to pay a ransom in exchange for data decryption key and program.

README.html ransom note dropped by Magniber ransomware virus
Screenshot of README.html ransom note.

The note instructs the user to download Tor browser and install it. Next, it suggests visiting a personal page created for the specific victim only. It appears that the virus assigns the personal website according to the extension generated and used to mark files on the infected computer.

In addition, the note contains several URLs that can be accessed via regular web browsers in case the victim doesn’t want to or doesn’t know how to install Tor browser. These URLs are likely to be taken down anytime, so the note suggests visiting them as soon as possible.

The payment site

The payment website assigned by the Magniber ransomware is dubbed “My Decryptor” and it suggests that the victim’s documents, photos, databases and other important files have been leaked and encrypted.

The page also states that the victim can get the decryption tools for “special price” only for 5 days, otherwise the ransom amount will be doubled. According to the site, the “special price” is 0.068 BTC ($2609) and the price after the increase will be 0.13600 BTC ($5218). Just like any other typical ransomware, it asks to make the transaction via cryptocurrency, specifically Bitcoin. Such transactions cannot be traced down, therefore FBI’s hands are tied when it comes to finding the perpetrators.

The TOR payment website of Magniber ransomware virus
The TOR website of Magniber ransomware.

In addition, the site claims that if the victim won’t purchase the decryption tools within 5 days, some data stolen from the computer will be sent to victim’s contacts and also published online.

When it comes to the ransom price, we can say that the operators behind this malware are rather greedy when it comes to the price of the decryption tools they offer.

Moreover, this ransomware strain doesn’t use sophisticated distribution techniques, therefore we believe it mostly targets home computer users. As a result, the ransom demand is simply too high as such decryption prices are usually demanded from infected companies or governmental institutions.

Previously, the threat actors behind this ransomware were spotted using different distribution techniques that involved exploitation of Internet Explorer vulnerabilities and also disguising the malware as updates for MS Edge or Google Chrome browsers.

norbert webb author at geeksadvice.com
Norbert Webb

Norbert Webb is the head of Geek’s Advice team. He is the chief editor of the website who controls the quality of content published. The man also loves reading cybersecurity news, testing new software and sharing his insights on them. Norbert says that following his passion for information technology was one of the best decisions he has ever made. “I don’t feel like working while I’m doing something I love.” However, the geek has other interests, such as snowboarding and traveling.

Related posts:

  1. Fix Microsoft Compatibility Telemetry High CPU Usage (CompatTelRunner.exe) Microsoft Compatibility Telemetry explained: what is it ContentsMicrosoft Compatibility Telemetry...
  2. Norton Security Review ContentsClose inspection of Norton Security softwareSystem requirements for those willing...
  3. Bitdefender Antivirus Free Edition Review Bitdefender Antivirus Free Edition 2018 reviewContentsBitdefender Antivirus Free Edition 2018...

Filed Under: News Tagged With: Magniber, Windows

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

SEARCH OUR SITE

Trending

decrypt files locked by stop djvu ransomware virus

Decrypt Files Locked by STOP/DJVU Ransomware (Updated 2023 Guide)

Some STOP/DJVU ransomware victims can decrypt or … [Read More...] about Decrypt Files Locked by STOP/DJVU Ransomware (Updated 2023 Guide)

Remove STOP/DJVU Ransomware Virus (2023 Guide)

STOP/DJVU in 2023: more than 670 versions, latest … [Read More...] about Remove STOP/DJVU Ransomware Virus (2023 Guide)

Remove Segurazo Antivirus (SAntivirus Removal Guide 2023)

Segurazo review: is it a virus? Segurazo … [Read More...] about Remove Segurazo Antivirus (SAntivirus Removal Guide 2023)

easy ways to fix dns_probe_finished_nxdomain error on windows, mac, android, chromebook

Fix DNS_PROBE_FINISHED_NXDOMAIN Error (Windows, Mac, Android, Chromebook)

DNS_PROBE_FINISHED_NXDOMAIN error … [Read More...] about Fix DNS_PROBE_FINISHED_NXDOMAIN Error (Windows, Mac, Android, Chromebook)

POPULAR SOFTWARE REVIEWS

Private Internet Access Review

Private Internet Access Review 2023: Fast, Secure & Cheap VPN

Private Internet Access (PIA) VPN maintains its long-term role as a leader Private Internet … [Read More...] about Private Internet Access Review 2023: Fast, Secure & Cheap VPN

restoro review 2020

Restoro Review 2023: Best Windows Repair Tool?

What is Restoro and how it works? Restoro is primarily a PC repair software designed for Windows … [Read More...] about Restoro Review 2023: Best Windows Repair Tool?

INTEGO antivirus review for Mac 2021

Intego Antivirus Review: Best Mac Antivirus in 2023?

Intego Antivirus for Mac is probably the best security choice for OS X Intego Antivirus for Mac … [Read More...] about Intego Antivirus Review: Best Mac Antivirus in 2023?

OUR EXPERTS RECOMMEND

Comprehensive PC Repair Software

geek's advice recommends restoro pc repair as editors choice
DOWNLOAD NOW
  • Uses Avira engine to remove malware
  • Repairs Virus Damage
  • Fixes Windows Errors & BSOD
  • Replaces Damaged DLLs
  • Repairs Damaged Windows Settings
  • Identifies Hardware Problems

Compatible with Microsoft Windows.

Read Full Review

Robust Mac Antivirus

geek's advice recommends intego mac internet security x9 as editors choice
GET INTEGO
  • 24/7 real-time protection
  • Intelligent firewall
  • Scans emails for malware
  • Scans iOS devices & external drives
  • Excellent malware detection rate
  • Easy-to-use

Compatible with Mac OS X 10.9-12.

Read Full Review

Copyright © 2023 Geeksadvice.com. Any unauthorized copying, redistribution or reproduction of part or all of the site contents in any form is prohibited.

About Us · Terms of Use · Privacy Policy · Contact Us