As security software and people become more aware of the methods that are used to distribute ransomware and malware, affiliates need to come up with craftier methods to infect their victims.
Such is the case with a new distribution method that overlays a fake Questions and Answers forum on top of the content of a hacked site. This fake forum post will contain information related to the content of the page that the user is visiting, so it appears that the answer and link offered by the admin is legitimate.
When someone visits the site for the first time, the script will cause a fake French Questions and Answers forum post to display over the content as shown below.
To the user, the above looks like the normal site as the content of the fake forum post is related to the content of the hacked page, but in reality is just an overlay created by the script.
If a user refreshes the page again, the script will not fire and the normal page will be shown as seen in the demonstration video at the end of the article.
If a user does not refresh the page, though, it will appear as if another visitor posted a question in French to the site about a “termination contract” for a photocopier model.
Always be suspicious about emails sent by unknown senders.
Do not respond to unexpected emails and do not click on links attached in unexpected emails.