Skype Users Be Warned: Ransomware Afoot

By Steve Anderson April 03, 2017

Scott Adams of Dilbert fame once noted that, wherever there was money, there would be weasels trying to lay hands on said money, and usually in a direct proportion. While Adams didn't quantify the exact weasel-to-dollars ratio—he suggested that such quantification would land someone a Nobel Prize—it was enough to note it existed. That particular connection has been abundantly demonstrated thanks to a new warning to Skype users: watch out for ransomware in the system.

More specifically, the ads are showing up through the Skype app, suggesting that it was a critical update for the Flash Web plug-in. The ad was found on the Skype home screen, and the world was notified via a thread on Reddit. The ad in question, when activated, would then begin a download of a HTML application, and when opened, the app would activate a payload of ransomware.

The ransomware delivery system's two-stage design—in which it requires a user to download a bit of JavaScript that in turn activates a covert download from a separate domain that contains the ransomware—makes it particularly adept at getting around antivirus tools. The good news is, reports note, the domain the original download pointed back to no longer exists, though future versions may have new domains.

Further good news may be afoot with the revelation of new admin tools for Skype for Business users. Microsoft recently rolled out the beta of a Call Analytics Dashboard that offers diagnoses of issues related to call quality.  While this may only have so much impact on an app that delivers malware via faulty link, if the dashboard in question can be set up to restrict pop-up advertising—since this is a beta, it's not clear where it will end up from here—that may nip this problem in the bud.

Even if it doesn't, there's still good news: since the ransomware in question requires an ad to be clicked on to activate, not clicking on an ad should deflect the worst of the trouble here. Since it can be so readily shut down, that means just a little vigilance on the user’s part should take care of a good chunk of this problem at the outset. Further, it's also worth noting that users need to remain vigilant in general, and should establish offline backups of files on any device. A USB hard drive, thumb drives, or even a separate computer not connected to the Internet will serve as an excellent means to keep files safe from ransomware.

Just a little extra vigilance should protect from this latest threat, and though the weasels mentioned earlier will always be with us, we have the means to protect ourselves against their depredations.




Edited by Alicia Young

Contributing Writer

SHARE THIS ARTICLE
Related Articles

Machine Learning & EHSQ: An Overview

By: Special Guest    7/21/2017

No matter what industry you work in, you've likely been hearing about the importance, and prevalence, of machine learning and analytics. But what do t…

Read More

10 Announcements From WWDC That Impact Mobile-First Businesses

By: Special Guest    7/20/2017

With several announcements made during Apple's annual WorldWide Developers Conference (WWDC), here are the top 10 that mobile-first businesses should …

Read More

How Artificial Intelligence is Changing the Travel Experience

By: Special Guest    7/20/2017

In tech circles and beyond, AI is the mot du jour lately, often thrown around in speculative conversations as the magical key that will unlock previou…

Read More

Attacking Democracy: Should DDoS Be Considered a Legitimate Form of Protest?

By: Special Guest    7/19/2017

It used to be that news about DDoS attacks was largely limited to tech websites and other specialized information sources, where the focus was on atta…

Read More

How AI is Changing the Way We Invest

By: Special Guest    7/14/2017

According to Investopedia, algorithmic trading already comprises 70 percent of daily trading. As trading becomes more automated, the need for human an…

Read More