Top: A variant of the Hidden-Tear Windows ransomware emerged in August 2016, masquerading as a Windows version of Pokémon Go and targeting Arabic users. This version of the malware includes several unique features not seen in other variants: It creates a user account called "Hack3r" on the victim's machine, such that even after the ransom was paid, the author still had a back door into the PC. Additionally, the ransomware copies itself onto all removable drives in the victim's PC, and sets itself to run automatically when an infected drive is inserted.
The screensaver ransom note here roughly translates as "Sorry, your files were unintentionally encrypted. To decrypt them, send 200 DZD Flexi Mobilis to the following account."
Bottom: Amusingly, the screensaver's executable contains an unused file, an image of Itachi Uchiha from the Naruto series titled "Sans Titre.png", "Untitled" in French.
Source: BleepingComputer












