Blind Eye Locker Ransomware: New Malware Encrypts Files and Displays Fake Windows Update
By
Tomas Meskauskas
Fresh out the oven, still warm. Top of the tray.
Summary
Blind Eye Locker is a ransomware program discovered by researchers on VirusTotal. When executed, it encrypts files on the victim's system, renames them with random character strings, and displays a fake Windows system update to deceive users. After encryption, it drops a ransom note named "README_" to demand payment for file decryption.
Key quotes
· 3 pulledOur research team discovered the Blind Eye Locker ransomware-type program while reviewing new malware submissions to VirusTotal.
Once we executed a sample of Blind Eye Locker ransomware on our test system, it began encrypting files and altered their filenames.
During the encryption process, it displayed a fake Windows system update.
You might also wanna read
Anonymous researcher releases two new Windows zero-day exploits after Patch Tuesday
An anonymous security researcher (Nightmare-Eclipse/Chaotic Eclipse) has released two new Windows zero-day exploits — YellowKey (a BitLocker
Anonymous researcher releases two new Windows zero-day exploits after Patch Tuesday
An anonymous security researcher (Nightmare-Eclipse/Chaotic Eclipse) has released two new Windows zero-day exploits — YellowKey (a BitLocker
Security researcher publishes YellowKey zero-day exploit that bypasses Microsoft BitLocker encryption via USB stick
Security researcher Chaotic Eclipse (Nightmare-Eclipse) has published two new zero-day exploits targeting Microsoft systems after their prev
Critical Misconfiguration in Microsoft's Internal Applications Exposes Sensitive Data
The article details a security researcher's discovery of a critical misconfiguration in Microsoft's internal applications, which allowed una
research.eye.security·9mo agoSecurity researcher claims BitLocker bypass vulnerability may be intentional Microsoft backdoor
A security researcher known as Nightmare-Eclipse has discovered and released YellowKey, a vulnerability that allegedly bypasses Microsoft's
GlassWorm: First Self-Propagating Worm Targets VS Code Extensions with Invisible Code
Researchers have discovered GlassWorm, the world's first self-propagating worm targeting VS Code extensions on the OpenVSX marketplace. This
JDownloader website hacked, served malware to Windows and Linux users for over a day
The JDownloader website was compromised by attackers who replaced legitimate download files with malware for over a day, targeting Windows a
