If you've received unexpected images on platforms like Facebook or LinkedIn in the past few days, the best thing you can do is ignore them completely. According to security firm Check Point, a new campaign of ransomware is trying to infect users through a very specific method: disguising the malicious payload as a JPG image. Everything points to this ransomware being a variant of the well-known Locky, which already caused trouble earlier this year.
The Year of Ransomware
2016 has undoubtedly been the year of ransomware. Its developers have confirmed that this data-holding tactic works very well, showing greater effectiveness when targeting specific places such as hospitals or government agencies. Faced with the possibility of losing information permanently, victims choose to pay the ransom and take measures afterwards, but with each success, ransomware becomes more complex. What is disturbing is that the perpetrators only need to modify existing ransomware to keep the wheel moving. Last February, Hollywood Presbyterian Medical Center paid the equivalent of 17,000 dollars in bitcoins, freeing its infrastructure from the ransomware called Locky. The presence of Locky decreased significantly after June, but if we go by Check Point's new report, it has returned in a very interesting way.
https://www.youtube.com/embed/sGlrLFo43pYImageGate: A New Attack Vector
As is customary, Check Point decided to name the campaign ImageGate. Basically, it's a new attack vector that covers ransomware under the guise of an image shared on social networks (with Facebook leading the way) and other platforms (LinkedIn was also mentioned). This is where the user's ignorance works against them. When clicking on the image link, what is actually downloaded is a file with SVG, JS, or HTA extensions, and in a typical case of 'curiosity killed the cat', double-clicking that file automatically triggers Locky. We all agree that it is too many chained errors on the user's part, but it is clear the campaign works.
How to Protect Yourself
Until online services implement the necessary protections to prevent threats like Locky from affecting millions of users, the first line of defense is none other than common sense. First of all, nobody should click on an unsolicited link, even if the contact is trusted (asking what it is beforehand is a good idea). And if for some reason you do click, it's critical to closely examine the file extension. As always: when in doubt, don't.