Home Malware Programs Ransomware dream_dealer@aol.com Ransomware

dream_dealer@aol.com Ransomware

Posted: February 1, 2018

The dream_dealer@aol.com Ransomware is a file-locking Trojan that belongs to the Globe Imposter Ransomware family. These Trojans pretend to be variants of the Globe Ransomware but use different, and often, less secure methods of blocking your media. Either backups or freeware decryptors may give you recovery options for anything that this Trojan damages and anti-malware products can prevent that harm by removing the dream_dealer@aol.com Ransomware as soon as it attacks your PC.

A New Imposter Handing out Bad Dreams

Unknown threat actors are deploying a new version of the Globe Imposter Ransomware, the Trojan group that delivers symptoms imitating the much more secure Globe Ransomware, but without much of the internally well thought-out coding practices. This version, the dream_dealer@aol.com Ransomware, is one of the few, verifiable members of its family for the new year. Others from the past one, showing almost the same symptomatic behavior, include the ABC Ransomware, the Kimchenyn Ransomware, the Decoder Ransomware and the Panda Ransomware.

Malware experts note that the dream_dealer@aol.com Ransomware is well into the deploying stage of its campaign, but how it's installing itself isn't yet determinable. Its payload includes an automatic file-locking feature that enciphers several, traditional formats of media, such as WAV sounds, Word and Adobe documents, and JPG or JPEG pictures. The '.DREAM' extension it also inserts, provides the victim with a visible cue for noting what content that the dream_dealer@aol.com Ransomware is keeping captured.

The dream_dealer@aol.com Ransomware also drops a text document that tells the user to contact the campaign's e-mail address for negotiating on purchasing the file-unlocking utility or decryptor. Although malware experts advise against paying, if possible, the threat actor does offer one, free decryption as proof, which the victim could use for restoring a particularly valuable file. While the dream_dealer@aol.com Ransomware's ransoming instructions do include some formatting errors, every other aspect of the Trojan's payload operates as intended.

Soundly Sleeping When Trojans Come Calling

The fact that the dream_dealer@aol.com Ransomware belongs to the Globe Imposter Ransomware family, and not that of the older Globe Ransomware, makes an essential difference to any data recovery solutions. The dream_dealer@aol.com Ransomware's family is non-secure and compatible with already-extant and free decryption programs, and malware experts see no justifications for paying the Trojan author's ransom for gaining access to a premium equivalent. Backups, as always, are even more ideal than reversing encryption for keeping your files as safe as possible from any Trojan with a data-locking payload.

Since threat actors with long-term funding and resources, typically, don't utilize AOL-based e-mail addresses, the dream_dealer@aol.com Ransomware's campaign is presumable as being a casual one safely. It could be circulating inside of e-mail attachments, bundling itself with illicitly-downloaded media, or using compromised advertising networks and fake update prompts. The anti-malware sector provides appropriate software for blocking all of these methods of attack and should uninstall the dream_dealer@aol.com Ransomware, like the other members of its family, easily.

The dream_dealer@aol.com Ransomware's maker may have much to dream about, but those dreams come at a price that others pay for him. Employing appropriate strategies in Web-browsing security and data preservation can help anyone with a computer sleep soundly.

Loading...