FBI MoneyPak Ransomware

{{Short description|Ransomware}}

{{Infobox computer virus

| fullname = FBI MoneyPak Ransomware

| image = File:Seal of the Federal Bureau of Investigation.svg

| caption = FBI logo used in the ransomware

| common_name = FBI Ransomware

| technical_name = Reveton Ransomware

| classification = Ransomware

| origin = United Kingdom

| language = English

|image2=File:Ransomware-pic.jpg|caption2=The ransom note left on an infected computer. The ransomware fraudulently claims that the user must pay a "fine" to the FBI.}}

The FBI MoneyPak Ransomware, also known as Reveton Ransomware, is a ransomware that starts by purporting to be from a national police agency (like the American Federal Bureau of Investigation) and that they have locked the computer or smartphone due to "illegal activities" and demands a ransom payment via GreenDot MoneyPak cards in order to release the device.{{cite web|url=https://www.forbes.com/sites/davidwismer/2013/02/06/hand-to-hand-combat-with-the-insidious-fbi-moneypak-ransomware-virus/ |title=Hand-to-hand combat with the insidious 'FBI MoneyPak ransomware virus'|work=Forbes|access-date=4 January 2019}}{{self-published inline|date=April 2019}}{{cite web |title=Reveton ransomware|url=https://www.fbi.gov/audio-repository/news-podcasts-thisweek-reveton-ransomware/view |publisher=FBI|date=10 August 2012|access-date=1 April 2019}}

Operation

The FBI ransomware starts often by being downloaded accidentally or visiting a corrupt website and running an application with a modified JavaScript code. The virus starts with a splash screen that contains the FBI's official logo with a warning that the computer has been locked. Depending on the version, the reason given is mainly either because of alleged copyright violations and/or because of purported child pornography offences.{{cite web|url=https://www.fbi.gov/news/stories/new-internet-scam|title=New Internet scam|publisher=FBI|date=9 August 2012|access-date=4 January 2019}} Sometimes other crimes, such as terrorism and gambling are included.{{Cite web|url=https://www.fbi.gov/news/stories/ransomware-abettor-sentenced-120618|title=Ransomware Abettor Sentenced — FBI}} It will also show the supposed IP address and sometimes a still from the user's webcam. The virus then demands between $100 and $1000 paid via pre-paid MoneyPak cards in order to release the infected hardware. If the payment is not made, then it alleges it will open a criminal investigation into the owner. The virus creates an iframe loop which prevents the user exiting the browser or website.{{cite web|url=https://www.cyber.nj.gov/threat-profiles/ransomware-variants/fbi-moneypak-ransomware|title=FBI MoneyPak ransomware|publisher=Government of New Jersey|date=5 July 2016|access-date=4 January 2019}} The virus will be installed on the infected device so it still requires removal from the device.{{cite web|url=https://www.bleepingcomputer.com/virus-removal/remove-fbi-monkeypak-ransomware|title=Remove the FBI MoneyPak ransomware or the Reveton trojan|publisher=bleepingcomputer.com|date=5 July 2012|access-date=4 January 2019}}

Reaction

In 2012, the FBI published advice relating to the FBI MoneyPak virus, telling people not to pay the ransom as it was not from the official FBI and confirmed it was not the real FBI who had locked the computers.{{cite web|url=https://www.fbi.gov/news/stories/ransomware-abettor-sentenced-120618|title=Ransomware abettor sentenced|publisher=FBI|date=6 December 2018|access-date=4 January 2019}} They also stated that users should go through authorized PC security firms to remove the ransomware or inform the IC3 – Internet Crime Complaint Center. In 2018, the FBI announced that working with the United Kingdom's National Crime Agency (NCA), they had arrested a number of people distributing the malware in the United States and that the NCA had arrested the creator of the virus in the United Kingdom.

Some people had been fooled into thinking that the virus was a legitimate warning from the FBI. One man complained about the FBI blocking his phone for child pornography which was attributed to the virus; however, he had admitted that he did have child pornography and was arrested by the police.{{cite web|url=https://www.cnet.com/news/man-gets-fake-fbi-child-porn-alert-arrested-for-child-porn/|title=Man gets fake FBI child porn alert, arrested for child porn |work=CNET |date=26 July 2013|access-date=4 January 2019}}

References