Ransomware campaign hits Germany
Fraudsters are sending phishing emails to German citizens, impersonating Federal Ministry of Health and distributing ransomware.
Since few days ago e-mails that are impersonating the Federal Ministry of Health are being sent to German citizens. In these e-mails there is a Word document that is titled ‘Family and sick leave’ – due to the pandemic it is a popular topic now.
Instead of the application form for paid leave the file after opening loads the Trojan Trickbot. This Trojan is then encrypting everything on the device.
To decrypt the data on your device you have to pay the ransom. The message seems to be prepared very well, seems authentic.
Always remember to:
- check the sender address,
- scan the e-mail and attachments before opening (you can use VirusTotal),
- check official government website for forms and applications, don’t use the ones sent to you,
- be wary of .doc, .xls, .pdf, .exe, .js, .zip, .rar extensions.