Home Malware Programs Trojans CIA Special Agent 767 Screen Locker

CIA Special Agent 767 Screen Locker

Posted: December 15, 2016

Threat Metric

Threat Level: 8/10
Infected PCs: 37
First Seen: December 15, 2016
OS(es) Affected: Windows


The 'CIA Special Agent 767' Screen Locker is a variant of the 'M4N1F3STO Virus' Lockscreen, a Trojan that blocks your access to the desktop and other programs with a pop-up message. Like its previous version, the 'CIA Special Agent 767' Screen Locker uses misleading and fraudulent information to coerce any victims into paying a ransom. Following the instructions in this article and using anti-malware solutions for removing the 'CIA Special Agent 767' Screen Locker can unlock your computer for free.

A Special Agent on the Case of Your Computer

Although the technical simplicity of using threatening encryption attacks causes many threat actors to use it as a bargaining chip, some con artists prefer a 'bare minimum' approach. When they're uninterested in creating or renting the code for legitimate encryption payloads, they may use simpler attacks misleading the victim only into believing that their media is the subject of such an attack. The 'M4N1F3STO Virus' Lockscreen was one of the most recent campaigns in this style, but malware experts are observing a new follow-up, the 'CIA Special Agent 767' Screen Locker.

The 'CIA Special Agent 767' Screen Locker's payload consists of loading a no-border, pop-up Web page that it uses for blocking your whole screen. This page contains CIA referential graphics and a warning stating that documents and other files are under an encryption cipher. Through a built-in interface, it redirects the reader to a Bitcoin-purchasing website and a transfer process for paying a ransom to a Bitcoin wallet address. The message claims that the entity will deliver the 'decryption key' for restoring your data within twenty-four hours after the payment.

Although it doesn't use a timer, the Trojan also tries to encourage quick payouts by cautioning you that the ransom may increase over time, up to 500 USD.

The Real Secret of this Secret Agent Man

Like 'M4N1F3STO Virus' Lockscreen, malware experts confirm that the 'CIA Special Agent 767' Screen Locker doesn't include any encoding features. It also doesn't try to commit other forms of file damage, such as deleting Shadow Copies. The greatest danger a 'CIA Special Agent 767' Screen Locker infection represents to your PC is its window's capacity for blocking your access to other applications, although any threats installing it may include other attacks.

The 'CIA Special Agent 767' Screen Locker's threat actor chose to use the same unlocking password for this Trojan as malware experts confirmed with the previous Trojan. Entering 'suckmydicknigga' into the key field should remove the warning message. Although the 'CIA Special Agent 767' Screen Locker has no especial defenses against deletion, victims are recommended to use anti-malware products for removing the 'CIA Special Agent 767' Screen Locker due to the likelihood of other threats factoring into the compromise of your PC.

The 'CIA Special Agent 767' Screen Locker is most threatening for PC users who assume that any warning appearing on their screens is legitimate and they should follow it without any questions. The next time you see the 'CIA' on your computer, you may want to stop and check for red flags, like requests for an untraceable cryptocurrency, before you do whatever the message says.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 290.43 KB (290430 bytes)
MD5: 3c74f228af8d9bd3b329a59cfb45e112
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 15, 2016
Loading...