DATA DOCTORS

Blackshades RAT and your computer

May 22, 2014, 12:00 PM | Updated: Jun 5, 2014, 9:58 pm

Q: How can I tell if my computer has been infected by the Blackshades malware ring that the FBI just broke up?

A: Last week, one of the most aggressive international cybercrime crackdowns was conducted by law enforcement officials in over a dozen countries that snared more than 90 people.

The Blackshades Remote Access Tool — or RAT — was a $40 piece of software that the FBI estimates infected over 700,000 computers worldwide, many of them in the U.S.

Blackshades is one of the many malicious tools which target Internet-connected computers that even a novice can use and once installed, allows a remote user total control of your system.

The high-profile ‘sextortion’ case of Miss Teen USA Cassidy Wolf, who was a victim of the Blackshades RAT, brought this particular underworld tool to the public’s attention, but there are many more.

Wolf was sent an anonymous extortion email message that threatened to post nude images of her that were captured from her webcam by a remote hacker that turned out to be a former schoolmate.

Remote Access Tools are actually legitimate programs used by IT departments to help support users, but Blackshades had various nefarious tools built-in that allowed a remote user to record keystrokes to steal passwords, activate webcams to silently take pictures and video of victims and encrypt data files so that users would have to pay a ransom to regain access to their own files.

Blackshades uses an obfuscation technique which constantly changes its appearance to avoid detection by traditional anti-virus programs, which contributed to its worldwide usage by hackers.

Typically, the attack vector was a cleverly crafted email scam or a cleverly disguised link on social media that convinced victims to allow the program to be installed without their knowledge.

Even though most everyone is well aware of the dangers of opening file attachments in email messages, the crafty social engineering tactics by hackers continue to fool people into a false sense of security.

RAT’s can make their way into your computer from email scams, drive-by downloads that exploit computers that don’t have the latest updates or as a hidden program in what appears to be a legitimate download.

The possible indicators of an infection by Blackshades or any other RAT according to the FBI can vary widely, but some of them include:

• Webcam indicator lights that randomly turn on when you aren’t using the webcam;

• Mouse cursors that move erratically by themselves;

• A display that suddenly goes dark by itself while you are using it;

• Text-based chat windows that appear unexpectedly;

• Inaccessible computer files that ask for an encryption key.

If you’re comfortable under the hood, another step is to examine the Windows Registry for an unusual entry that contains a random string of letters and numbers that include the subkey of ‘SrvID’.

If your computer is running slow, takes forever to start up or seems really sluggish when you try to begin surfing the web, these are all indications that things are not as they should be.

Slow or unusual performance is not a certain indication of infection but is always an indication that something is not right, so don’t ignore these symptoms.

Data Doctors

How to sync smartphones to Windows computers: Arizona tips...

Data Doctors

Tech tip for Arizonans: How to sync smartphones to Windows computers

Want to learn how to sync smartphones to Windows computers? This article from the Data Doctors explains which steps to take.

4 days ago

(Pexels photo)...

Ken Colburn, Data Doctors

Here’s what a Wi-Fi analyzer app is used for

Wi-Fi has become an essential utility for most homes and making sure the signal is adequate in high usage areas is key.

11 days ago

(Pexels File Photo)...

Data Doctors

Here are all of the pros and cons of HP’s All-In printer plan

Each brand tries to differentiate itself from the rest of the crowd by creating unique features and in HP’s case, the subscription model is their latest offering.

18 days ago

Many of the fake videos you’ll encounter are likely to be viewed on your smartphone, which can ma...

Data Doctors

Here are all the tips we know regarding how to spot deep fake videos

Many of the fake videos you’ll encounter are likely to be viewed on your smartphone, which can make detection a bit more difficult.

25 days ago

Patrick Mahomes #15 and head coach Andy Reid of the Kansas City Chiefs are recorded on a phone as t...

Data Doctors

Handy tech tips all Valley residents should use to find lost phones in a snap

Q: My phone went missing, and I haven’t been able to locate it using the Find My service, so what should I do next?

1 month ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are tips for freeing up Google storage space

Google provides a generous amount of free online storage but it can fill up quickly depending on how many of its resources you use.

1 month ago

Sponsored Articles

...

DISC Desert Institute for Spine Care

Sciatica pain is treatable but surgery may be required

Sciatica pain is one of the most common ailments a person can face, and if not taken seriously, it could become one of the most harmful.

...

Day & Night Air Conditioning, Heating and Plumbing

Day & Night is looking for the oldest AC in the Valley

Does your air conditioner make weird noises or a burning smell when it starts? If so, you may be due for an AC unit replacement.

...

Fiesta Bowl Foundation

The 51st annual Vrbo Fiesta Bowl Parade is excitingly upon us

The 51st annual Vrbo Fiesta Bowl Parade presented by Lerner & Rowe is upon us! The attraction honors Arizona and the history of the game.

Blackshades RAT and your computer