Blackshades RAT and your computer

May 22, 2014, 12:00 PM | Updated: Jun 5, 2014, 9:58 pm

Q: How can I tell if my computer has been infected by the Blackshades malware ring that the FBI just broke up?

A: Last week, one of the most aggressive international cybercrime crackdowns was conducted by law enforcement officials in over a dozen countries that snared more than 90 people.

The Blackshades Remote Access Tool — or RAT — was a $40 piece of software that the FBI estimates infected over 700,000 computers worldwide, many of them in the U.S.

Blackshades is one of the many malicious tools which target Internet-connected computers that even a novice can use and once installed, allows a remote user total control of your system.

The high-profile ‘sextortion’ case of Miss Teen USA Cassidy Wolf, who was a victim of the Blackshades RAT, brought this particular underworld tool to the public’s attention, but there are many more.

Wolf was sent an anonymous extortion email message that threatened to post nude images of her that were captured from her webcam by a remote hacker that turned out to be a former schoolmate.

Remote Access Tools are actually legitimate programs used by IT departments to help support users, but Blackshades had various nefarious tools built-in that allowed a remote user to record keystrokes to steal passwords, activate webcams to silently take pictures and video of victims and encrypt data files so that users would have to pay a ransom to regain access to their own files.

Blackshades uses an obfuscation technique which constantly changes its appearance to avoid detection by traditional anti-virus programs, which contributed to its worldwide usage by hackers.

Typically, the attack vector was a cleverly crafted email scam or a cleverly disguised link on social media that convinced victims to allow the program to be installed without their knowledge.

Even though most everyone is well aware of the dangers of opening file attachments in email messages, the crafty social engineering tactics by hackers continue to fool people into a false sense of security.

RAT’s can make their way into your computer from email scams, drive-by downloads that exploit computers that don’t have the latest updates or as a hidden program in what appears to be a legitimate download.

The possible indicators of an infection by Blackshades or any other RAT according to the FBI can vary widely, but some of them include:

• Webcam indicator lights that randomly turn on when you aren’t using the webcam;

• Mouse cursors that move erratically by themselves;

• A display that suddenly goes dark by itself while you are using it;

• Text-based chat windows that appear unexpectedly;

• Inaccessible computer files that ask for an encryption key.

If you’re comfortable under the hood, another step is to examine the Windows Registry for an unusual entry that contains a random string of letters and numbers that include the subkey of ‘SrvID’.

If your computer is running slow, takes forever to start up or seems really sluggish when you try to begin surfing the web, these are all indications that things are not as they should be.

Slow or unusual performance is not a certain indication of infection but is always an indication that something is not right, so don’t ignore these symptoms.

Data Doctors

(Pexels Photo)...
Data Doctors

Here’s what we know about Facebook’s potential new monthly charge

It was easy to tell anyone that anything claiming Facebook would start charging users was a hoax, but all that changed last month.
5 days ago
(Photo by Phil Barker/Future Publishing via Getty Images)...
Data Doctors

A brief explainer on signs your computer could be infected

If you own a computer, here's a list of signs that could help you determine if your device has been infected.
12 days ago
(Pexels Photo)...
Data Doctors

Understanding email subscription notifications spamming

What you experience is "subscription bombing" used for reasons that can range from being a nuisance to distracting you from other activities.
19 days ago
(Mesa Police Department Photo)...
KTAR.com

Mesa police seeking 27-year-old woman wanted in murder case

Mesa police are searching for a 27-year-old woman wanted in a murder case after a man was found dead inside a bedroom in early February.
23 days ago
(Pexels Photo)...
Data Doctors

Benefits and concerns with using 3rd-party authentication apps

An alternative to setting up the text messaging-based authentication is by installing an app that provides the authentication codes.
26 days ago
(Photo by Phil Barker/Future Publishing via Getty Images)...
Data Doctors

What to know when buying a processor for a new computer

If you use your computer for complex tasks such as gaming, editing or programming, you’ll need to pay attention to the processor you buy.
1 month ago

Sponsored Articles

(Photo: OCD & Anxiety Treatment Center)...

Here’s what you need to know about OCD and where to find help

It's fair to say that most people know what obsessive-compulsive spectrum disorders generally are, but there's a lot more information than meets the eye about a mental health diagnosis that affects about one in every 100 adults in the United States.
...
Day & Night Air Conditioning, Heating and Plumbing

Company looking for oldest air conditioner and wants to reward homeowner with new one

Does your air conditioner make weird noises or a burning smell when it starts? If so, you may be due for an AC unit replacement.
(Photo via MLB's Arizona Fall League / Twitter)...
Arizona Fall League

Top prospects to watch at this year’s Arizona Fall League

One of the most exciting elements of the MLB offseason is the Arizona Fall League, which began its 30th season Monday.
Blackshades RAT and your computer