Fantom, a new ransomware discovered recently, strikes disguised as a legitimate Microsoft Windows update. Thus it tricks users into downloading it, thereby paving the way for data breach…
Malware researcher Jakub Kroustek of security firm AVG has discovered this rather sophisticated malware.

Ransomware, as we know, refers to the malware that helps hackers block systems and encrypt users’ files in such a way that they cannot be opened or used.

Ransomware also stops apps from running. Thus the person who is affected will have to pay a ransom to the hacker(s) to get his system back on track or to open and use files and apps.

Ransomware attacks are increasing in number these days; many are the organizations that have fallen prey to ransomware attacks in recent months.

How Fantom Works…

Fantom, which is a ransomware based on the open-source EDA2 ransomware project, appears displaying a fake Windows Update Screen. This update screen leads you into believing that Windows is installing a new critical update. Even the file properties for the ransomware would make you believe that, stating that it’s from Microsoft and will have the file description as ‘Critical Update’.

fantom-update

Led into believing that it’s a genuine Windows update, you might execute it. This will make the ransomware extract and execute another embedded program called WindowsUpdate.exe and then a fake Windows Update screen will be displayed.

This screen will overlay all active Windows and you won’t be able to switch to any other open application.

You’d see on this update screen a percentage that leads you into believing that the Windows update is taking place while in reality your files are being encrypted as the percentage increases.

Though Ctrl+F4 key combination could help you close this screen if you want, the file encryption would carry on in the background.

Fantom, like other EDA2-based ransomware, will generate a random AES-128 key and encrypt it using RSA. Then it will be uploaded into the Command & Control server of the malware developers. Then it scans local drives for files that contain targeted file extensions.

These files are encrypted using AES-128 encryption, to each encrypted file will be added the extension .fantom. In folders wherein Fantom encrypts files, a ransom note DECRYPT_YOUR_FILES.HTML will also be created.

When the encryption is done, Fantom will create two batch files that are executed; these will delete the shadow volume copies and the fake update screen which you had got earlier.

These files are encrypted using AES-128 encryption, to each encrypted file will be added the extension .fantom. In folders wherein Fantom encrypts files, a ransom note DECRYPT_YOUR_FILES.HTML will also be created.

When the encryption is done, Fantom will create two batch files that are executed; these will delete the shadow volume copies and the fake update screen which you had got earlier.

When the encryption is done, Fantom will create two batch files that are executed; these will delete the shadow volume copies and the fake update screen which you had got earlier.

Then finally comes the ransom note called DECRYPT_YOUR_FILES.HTML. This will have the mention that restoring your data would be possible only by buying passwords from them.

There will be the instructions to email [email protected] or [email protected] so that you could receive payment instructions. You’re also warned not to try to restore files saying that it could destroy your data completely.

There will be the instructions to email [email protected] or [email protected] so that you could receive payment instructions. You’re also warned not to try to restore files saying that it could destroy your data completely.

There will be the instructions to email [email protected] or [email protected] so that you could receive payment instructions. You’re also warned not to try to restore files saying that it could destroy your data completely.

Fantom ransomware removal:

STEP 1. Fantom virus removal using safe mode with networking.
STEP 2. Fantom ransomware removal using System Restore.

 

If you cannot start your computer in Safe Mode with Networking (or with Command Prompt), boot your computer using a rescue disk. Some variants of ransomware disable Safe Mode making its removal complicated. For this step, you require access to another computer.

To regain control of the files encrypted by Fantom, you can also try using a program called Shadow Explorer. More information on how to use this program is available here.

shadow-explorer-screenshot

To protect your computer from file encrypting ransomware such as this, use reputable antivirus and anti-spyware programs like comodo. As an extra protection method, you can use programs called HitmanPro.Alert and EasySync CryptoMonitor.

HitmanPro.Alert CryptoGuard – detects encryption of files and neutralises any attempts without need for user intervention:

hitmanproalert-ransomware-prevention1

EasySync CryptoMonitor – kills an encryption infection and blacklists it from running again:

cryptomonitor-ransomware-prevention2

There are some Other tools known to remove Fantom ransomware.</p></h5>

Gurubaran is a PKI Security Engineer. Certified Ethical Hacker, Penetration Tester, Security blogger, Co-Founder & Author of GBHackers On Security.