Home Malware Programs Ransomware BlackSheep Ransomware

BlackSheep Ransomware

Posted: May 30, 2017

Threat Metric

Threat Level: 10/10
Infected PCs: 55
First Seen: May 30, 2017
OS(es) Affected: Windows


The BlackSheep Ransomware is a Trojan that locks your files while pretending to be part of a Windows update. However, the Bitcoin ransoms this threat requests in exchange for giving you a decryption solution are redundant in comparison to the free solutions offered by the PC security sector. Malware experts also advocate for backing up any valuable files and using anti-malware programs for removing the BlackSheep Ransomware, whether before or after its install attempt.

The Fluffiest Brand of Extortion

A new member of the FTSCoder family is in live distribution as of late May and includes an operating system-specific way of hiding its attacks. With a social engineering exploit similar to the unrelated SecretSystem Ransomware, the BlackSheep Ransomware blocks files on an infected PC while keeping users from interrupting it by hiding itself behind a Windows update screen. Like most threat actors, the BlackSheep Ransomware's author is launching such attacks to collect Bitcoins afterward.

The BlackSheep Ransomware is circulating through unknown methods, but other Trojans with non-consensual encryption functionality may install themselves from e-mail attachments or corrupted website content. Its attacks encrypt JPG pictures, DOC documents, and other media with an algorithm meant to block other programs from opening them. Simultaneously, it also loads a no-border window with a fake Windows update image. Current samples include a notice with a typo ('untill') that victims can use to help identify the fraudulent notification.

Then, the Trojan replaces the first pop-up with a secondary one, which malware experts warn can lock your screen, thereby blocking access to the desktop. This new, HTML-based window reveals the BlackSheep Ransomware's identity while asking for a Bitcoin ransom equal to 500 USD. The threat actors also built several 'user-friendly' features into this attack, such as a decryption key field and a support button.

Shearing the BlackSheep Ransomware's Ransom Money

The BlackSheep Ransomware's authors are warning their victims to pay within fifty-four hours before facing additional consequences, such as the deletion of the decryption key. However, like most versions of BTCWare, the BlackSheep Ransomware is decryptable by a free software developed by the PC security sector. For threats more advanced than the BlackSheep Ransomware, but showing similar symptoms, malware analysts endorse using remotely-saved backups for an even more secure data recovery choice.

Threat actors may obfuscate the BlackSheep Ransomware inside of compressed RAR archives or disguise it as non-toxic content such as an e-mail memo. Since this Trojan causes substantial data loss, albeit temporarily, most users should try to block the installation exploits that lead to an infection. Anti-malware products of various brands can uninstall the BlackSheep Ransomware, although recovery of any locked content is, as noted previously, the purview of more specialized software.

As usual, paying attention to details pays off for any PC user with even the most superficial familiarity with what is and isn't secure or standardized for the Windows systems. Hopefully, the BlackSheep Ransomware's authors will not update this threat to make its disguise any more convincing.

Loading...