Beware of 'Big Head' Ransomware: Fake Windows Update Alert Threatens Data

Security researchers have analyzed a new ransomware strain called 'Big Head' that is believed to be spreading through malvertising campaigns promoting fake Windows updates and Microsoft Word installers. The ransomware, written in .NET, installs encrypted files on the target system for propagation, Telegram bot communication, and file encryption. It also displays a fake Windows update screen during the encryption process. Multiple variants of Big Head have been identified, with some incorporating data-stealing capabilities and file infection techniques. While not highly sophisticated, the ransomware targets consumers who may be easily tricked or lack cybersecurity awareness. The main author of Big Head is suspected to be of Indonesian origin, according to cyber-intelligence firm KELA.
- New ‘Big Head’ ransomware displays fake Windows update alert BleepingComputer
- 'Big Head' malware threat looms, warn researchers SC Media
- Beware! Big Head ransomware that looks like Windows update can also delete backups Neowin
- "Big Head" ransomware fakes Windows Update to trick users Ghacks
- View Full Coverage on Google News
Reading Insights
0
1
3 min
vs 4 min read
85%
740 → 112 words
Want the full story? Read the original article
Read on BleepingComputer