Jump to content

Malware Extorts Cash From BitTorrent Users


nsane.forums

Recommended Posts

nsane.forums

ICCP Foundation claims to be an international company operating out of Switzerland. They say they are “committed to promoting the cultural and economic benefits of copyright” while assisting their partners to fight “copyright theft around the world”.

In fact what they really do is operate a scam to extort money from BitTorrent users.

Right at this moment we are unsure of the exact route of infection, but somehow malware (probably in either fake file or attached virus form) is displaying a “copyright violation alert” on the victim’s screen, locking it, and redirecting users to the ICPP site where they are told they have been caught infringing copyright.

icpp1.jpg

There they are warned their offenses could result in 5 years in prison and a $250,000 fine and are given the option to take the (fake) case to court. They are also offered a chance to make the whole thing go away for the payment of a ‘fine’ of around $400. Victims are also prompted to give their name, address and full credit card details – it is unclear how this information is further abused but it doesn’t look good.

icpp3.jpg

If they select the court option, they are scared with this screen:

icpp2.jpg

So that that this evil software (believed to be located at C:Documents and SettingsAdministratorApplication DataIQManageriqmanager.exe) more accurately targets BitTorrent users rather than just random users, it appears to scan the user’s hard drive for .torrent files and displays these as ‘evidence’ of an earlier infringement.

In order to boost their credibility, icpp-online.com claim to be affiliated with influential partners – the RIAA, MPAA, and The Copyright Alliance. Of course, this is a complete fabrication.

This whole approach seems very similar to that employed by so-called ‘rogue software‘ or ’scareware’ which attempt to frighten users into parting with cash for often useless software. And it seems the links to malware don’t stop there.

A WHOIS on the ICPP-Online domain reveals some contact data which shows up elsewhere in connection to other questionable activities.

Details on this new threat are scarce at the moment, so if any readers can discover more about this malware or the operation behind it, please collate the information and send it over to [email protected]

Article from: TorrentFreak, check out our new blog at FreakBits.

view.gif View: Original Article

Link to comment
Share on other sites


  • Replies 0
  • Views 846
  • Created
  • Last Reply

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...