Municipality of The Hague hit by TorrentLocker malware

Spread the love

The municipality of The Hague has been hit by the TorrentLocker ransomware. Four employees opened a link and their PCs are said to have been infected by the malware. The malware encrypts users’ files and asks them for money to decrypt those files again.

A total of four computers belonging to the municipality were affected, Security.nl reports. The employees opened a message that contained a link to a website that, in turn, contained the malware. After half an hour, the ICT department of the municipality identified the infection and the e-mail server was temporarily disabled. The infected computers, which have since been recovered, are said to have contained no confidential data.

The ransomware spreads by searching for email addresses of contacts in Thunderbird, Outlook, and Windows Live Mail. In addition, he searches for passwords to log in to mail accounts. Intended victims receive an email with a link to what appears to be a track & trace page of a postal company. After the introduction of a captcha, the site offers a zip file containing a PDF-like executable. This malware then starts encrypting accessible files.

Users have to pay to access the files again. This method, which was previously used by the authors of the Cryptolocker malware, among others, would have yielded the attackers a quarter of a million euros. As far as we know, no other governments have been affected by the TorrentLocker ransomware yet.

You might also like