1310 Nowell Road
Raleigh, NC 27607
Existing CSP Client: (919) 424-2060
SALES: (919) 420-3231
Although it’s not a very well-written program, and it hasn’t been transmitted in spam email blasts, the Troj/Fantom-B (as it’s pegged by ransomware-blocker Sophos) or Fantom ransomware does, nevertheless, masquerade as a Windows 10 “critical” update, and will mess up your files and demand money from unwitting email users when it successfully fools recipients. It’s an all-too-familiar ransomware scenario, which may work in email users’ favor.
The bad news is that this latest ransomware scam program works effectively if it gets past your computer security, or you inadvertently click on it. The fact that Fantom is obviously written by illiterate cyber crooks won’t matter once it gets into your device’s system. It was, unfortunately, written at least well enough for that. It can encrypt your data files soon after being unwittingly downloaded, but it’s the “pay page” that really shows the room-temperature IQ-levels of the hackers that threw this one together.
Is Fantom evidence that the world of ransomware and hacking is opening up to lower levels of cybercriminal opportunists? They were able to write the malware program in C#, which shows the Fantom authors’ lack of knowledge about programming or cryptography. Be sure your email spam filters are leveled-up, though, because Fantom may be lurking behind the requisite fake invoices and requests for a quotation, which are two very common and effective email fronts for ransomware assaults.
How Fantom Works
Masquerading as a Microsoft critical update to Windows, it sends you a .exe file, which is the first red flag. You see, critical Windows updates will NEVER be sent to you via an email attachment – and especially not without a digital, proprietary Microsoft signature, as Fantom lacks. If Fantom gets up and running on your device, you will see a box with two new processes, listing:
1) Critical update (32-bit), and
2) WindowsFormsApplication5.
The critical update file is the one that does the file scrambling while the secondary and oddly-named WindowsFormsApplication5 file is set into motion by the first one and used merely as a decoy. While the second one distracts you, the “critical update” runs through your files and renames them with the extension “.fantom” (as fast as the malware can get through your database).
You will then see a somewhat legitimate-looking animated full-sized window with white lettering on a blue background that says:
Configuring critical Windows Updates
1% complete
Do not turn off your computer.
If you are a quick hand, you can hit Ctrl-Alt-Esc and access the task manager, and from there terminate both ransomware processes. Some aren’t so fast, or aren’t aware of its presentation, and as a result end up getting a significant amount of their files screwed-up by this fake Windows update.
Backed-up Files Fight Ransomware
Remember that the best way to fight the current ransomware scourge is to have your data files completely backed-up on an external or off-site (cloud) storage. Along with that, never pay the ransom demands, but instead call a managed IT services provider immediately to have them walk you through the ransomware elimination. Not having one in the first place to guide you on the finer points of beating ransomware is likely why you became a ransomware victim in the first place.
Get Trusted IT Pros on the Job
If you have questions about getting ransomware-fighting cybersecurity for your company network set up, Raleigh IT Support Company and IT Services Provider | CSP Inc. is the leader in providing managed IT services in Raleigh. Contact one of us today at (919) 424-2000 or send us an email at info@cspinc.com, and we will be happy to answer all your questions.
Always at your service to provide the highest level of quality support to our customers.
Anthony Firth Client Engineer
“I’m passionate about building and fostering relationships, and finding solutions for success.”
Michael Koenig Client Account Manager
“I help clients stabilize and grow their IT infrastructure so they can focus on growing their core business.”
Josh Wilshire Systems Engineer Team Lead
“I strive to provide the highest level of quality service to our customers.”
Tommy Williams Sr. Hardware Engineer
“I’m driven by the steadfast belief that technology must serve as a business enabler. This mantra has driven 21
Years of successful partnerships.”
Stephen Riddick VP Sales & Marketing
“CSP doesn’t succeed unless your company succeeds.”
Stephen Allen Inventory Manager
“Through my intuition and genuine concern to help others I have built long-lasting relationships with our customers, co-workers and business partners.”
Scott Forbes VP Support Services
“Every day, I work with clients to help plan the future of their businesses.”
Michael Bowman vCIO
“Your IT problems become our IT solutions.”
Mark McLemore Project Engineer
“Managing internal and external operations to ensure that CSP provides quality and reliable customer service .”
Margie Figueroa Business Manager
“Providing quality internal and externals financial support to our customers and accounting support to CSP.”
Katie Steiglitz Accounting Administrator
“Some call me the CEO. I call myself the Cheerleader for an awesome team!”
William B. Riddick Founder & CEO
“CSP is here to assist you with your IT needs.”
Beth Wylie Inside Sales Manager
On What Questions You Need To Ask Before Signing Any Agreement.
"*" indicates required fields
Raleigh IT Support Company and IT Services Provider | CSP Inc.
1310 Nowell Rd,
Raleigh, NC 27607
Existing CSP Client: (919) 424-2060
SALES: (919) 420-3231
Receive email updates and informative marketing materials by subscribing to our newsletter.
"*" indicates required fields