Stories
Slash Boxes
Comments

SoylentNews is people

posted by CoolHand on Tuesday August 16 2016, @04:28PM   Printer-friendly
from the vigilante dept.

Some may have heard of scambaiting spammers to waste their time and resources. There are many sites like 419eater which concentrate on it. However, Arthur T Knackerbracket has found the following story which takes things a step further. A French security researcher says he managed to turn the tables on a cyber-scammer by sending him malware. Whether or not that is ethical is left as an exercise for the readership.

But Ivan Kwiatkowski played along with the scheme until he was asked to send credit card details. He instead sent an attachment containing ransomware.

[...] When Mr Kwiatkowski's parents stumbled across one such website, he decided to telephone the company and pretend he had been fooled.

The "assistant" on the telephone tried to bamboozle him with technical jargon and encouraged him to buy a "tech protection subscription" costing 300 euros (£260).

Mr Kwiatkowski told the assistant that he could not see his credit card details clearly and offered to send a photograph of the information.

But he instead sent a copy of Locky ransomware disguised as a compressed photograph, which the assistant said he had opened.

"He says nothing for a short while, and then... 'I tried opening your photo, nothing happens.' I do my best not to burst out laughing," Mr Kwiatkowski wrote in his blog.

[...] Mr Kwiatkowski said he could not be absolutely certain whether the ransomware had infected the scammer's computer, but there was a fair chance it had.

"He did not let on that something had happened to his computer, so my attempt is best represented as an unconfirmed kill," said Mr Kwiatkowski.

"But encrypting a whole file system does take some time."

He acknowledged that some people may have found his retaliation unethical, but said responses had been "mostly positive".


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 4, Informative) by Anonymous Coward on Tuesday August 16 2016, @06:37PM

    by Anonymous Coward on Tuesday August 16 2016, @06:37PM (#388781)

    There is no 'mother'. The dude works in a sweat shop that does this for a living.

    From the blog 'He calls his superior in the hopes of figuring out why the payment isn't going through. In the meantime, I hear other operators in the background repeating credit card numbers and CVVs aloud.'

    Starting Score:    0  points
    Moderation   +4  
       Insightful=1, Informative=3, Total=4
    Extra 'Informative' Modifier   0  

    Total Score:   4  
  • (Score: 0) by Anonymous Coward on Tuesday August 16 2016, @09:21PM

    by Anonymous Coward on Tuesday August 16 2016, @09:21PM (#388838)

    > There is no 'mother'. The dude works in a sweat shop that does this for a living.

    How do you know that the shop provided the computer? That it isn't a laptop he had to bring from home?

    It is always *easy* to ascribe the most favorable conclusions to the limited number of facts we have. Kind of like how we know there have been no killing of innocent civilians by drone bombings because the military has declared that all teenage and adult males in the vicinity of a drone bombing are enemy combatants ergo no innocents killed. Easy and wrong.

    • (Score: 1, Interesting) by Anonymous Coward on Tuesday August 16 2016, @11:22PM

      by Anonymous Coward on Tuesday August 16 2016, @11:22PM (#388889)

      You also have *NO* idea there is a mother and he brought in his own hardware. Perhaps he brought his own phone in. Perhaps he built his own cubical? Perhaps the chair he was sitting on was brought from home too. Even *the* cheapest of Indian sweat shops provides computers. I know I have contracted out to many of them. They usually wipe them at the end of their contract.

      Kind of like how we know there have been no killing of innocent civilians by drone bombings because the military
      You also are conflating the fucking up a single computer with drone shootings? I'm sorry thats silly.

      I find it very difficult to feel sorry for someone trying to fuck up some old mans computer and rob him of 300 euros. At worst he has to reinstall his computer. At best he learned a lesson and moved onto better work. Your weak attempt to derail the conversation is silly. How is what the dude did to him *any* worse than what the guy was doing to him? Do you somehow thing that poor Indian guy on the other end was just going to nicely fix his computer? No he was going to screw it up and rob that guy. It was little more than a computer mugging that went wrong for the mugger.

      Again there is 'no mother'. That was made up to generate sympathy for a douche bag who steals for a living.