According to a report in India's Economic Times newspaper, the attackers compromised the computers of administrators in all four companies by sending them emails disguised as a communication from senior management. The ransomware was executed when the emails were opened.
The ransomware in question is known as LeChiffre and, according to the Malwarebytes Unpacked blog, it is different from most other Windows ransomware because, instead of spreading to users and automatically infecting their machines, LeChiffre needs to be run manually on a system to compromise it.
The blog noted that a common scenario would be one where attackers automatically scanned a network in search of poorly secured remote desktops, cracked them, and manually ran an instance of LeChiffre after logging in remotely. The ransomware encrypts files and appends an extension ".LeChiffre" to the files.
|
The attackers left a ransom note and contact details in a text file on each computer that was compromised.
The Economic Times said the companies had paid the ransom for some top executives' computers so that they could at least use them. It did not specify the version of Windows being used by any of the companies.
The attackers had demanded one bitcoin (currently about 30,000 Indian rupees or about A$635) for each computer that they had infected. This is the first time that a ransom in bitcoins has been sought in India.
In May 2015, the ET report said, two Indian conglomerates had found themselves facing a demand of about US$5 million each by attackers who had breached their systems and then threatened to pass on company information to the Indian government if their demands were not met. Both conglomerates had paid the ransom.
Microsoft has some details on ransomware on its website but there is no mention of LeChiffre.
Image: courtesy Microsoft