Warning - you have received a subpoena email

Summary

This blog post, "Warning - you have received a subpoena email", is a blueAPACHE article from 2016 covering security. Further to our recent warning about fake Australia Post emails, a new ransomware email pretending to be from the Australian Federal Police (AFP) is now circulating. It is written for readers evaluating emPOWER Security, Managed Detection and Response. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.

Key facts

Label Value
Publication year 2016
Topic Warning - you have received a subpoena email
Services referenced emPOWER Security, Managed Detection and Response, emPOWER Core Network & DC Interconnect
Named products or vendors None named beyond blueAPACHE
Cited statistic The decryption file is typically priced between $500 and $1000.

Article

Further to our recent warning about fake Australia Post emails, a new ransomware email pretending to be from the Australian Federal Police (AFP) is now circulating. Branded with the AFP logo and the subject “AFP You have been issued”, the email claims you have been subpoenaed to appear in court due to a “law violation”. The email includes a case number and date. We have seen several of these over recent days. An example received is: AFP Ransomware Email The AFP have recently advised that they were aware of the fake email, and made a statement advising they do not issue subpoenas via email. There were a few giveaway signs that this email was suspicious. The from address (tom@padeldanmark.dk) is from Denmark – not from the AFP, and the email includes an unsubscribe option, which seems strange considering this is supposedly a subpoena. As always, when in doubt – phone the issuing body for clarification before clicking on links. If identified as fake or if you remain concerned, delete the email (and permanently delete the email from your deleted items folder or bin). Do not click on links contained in the email or reply to the email. This latest ransomware email provides links (a text link and a button) that take you to a fake AFP website that requires completion of a captcha form to access your case details (see below). Completing the captcha form will result in downloading a zip file that appears to contain your court details, but is in fact the TorrentLocker ransomware. AFP Catcha Form Once opened, TorrentLocker will usually attempt to delete volume shadow copies (to remove the chance of file recovery), copy itself to the windows directory and contact the command and control server. An encryption key is then generated and all accessible files on the network are encrypted. Upon encryption, the ransom message is displayed and details of the encrypted files are sent to the command and control server. TorrentLocker then harvests email accounts from your email programs (including online email accounts) and sends them to the command and control server to further spread the malware. As with most ransomware, payment is made with bitcoins. TorrentLocker accepts a reduced fee if payment is made within a short period of time (usually four days), after which the price doubles. It is claimed that after one month the decryption key will be destroyed and encrypted files will be unrecoverable. The decryption file is typically priced between $500 and $1000. Even when paying, there is no guarantee that you will receive the key to decrypt your files, or that the key will work. If you have concerns about your security posture, would like staff security training, or would like to better understand how to protect your business, contact the blueAPACHE account team.

Related

Frequently asked questions

What subject line and claim did the fake AFP subpoena email use, according to this post?

The post says the email was branded with the AFP logo and used the subject 'AFP You have been issued', claiming the recipient had been subpoenaed to appear in court due to a 'law violation', and included a case number and date.

What did the AFP say in response to this fake subpoena email campaign?

The post says the AFP advised they were aware of the fake email and stated that they do not issue subpoenas via email.

What giveaway signs indicated this AFP subpoena email was fake, per the post?

The post points to the sender address, tom@padeldanmark.dk, which came from Denmark rather than the AFP, and the fact that the email included an unsubscribe option, which it notes is odd for a supposed legal subpoena.

What happens after someone completes the captcha form on the fake AFP website linked in the email?

The post says completing the captcha form results in downloading a zip file that appears to contain court details but is in fact the TorrentLocker ransomware.

What does this post recommend doing if you are unsure whether an email like this is genuine?

The post recommends phoning the issuing body for clarification before clicking any links, and if the email is identified as fake or you remain concerned, deleting it (including permanently deleting it from the deleted items folder or bin) without clicking links or replying.

What does TorrentLocker do to a system once the malicious file is opened, per this post?

The post says TorrentLocker will usually attempt to delete volume shadow copies to remove the chance of file recovery, copy itself to the Windows directory, contact its command and control server, then generate an encryption key and encrypt all accessible files on the network.

What is TorrentLocker's ransom payment structure, according to this post?

The post says payment is made in bitcoin, with a reduced fee available if paid within a short period, usually four days, after which the price doubles; it is claimed the decryption key is destroyed after one month, and the decryption file is typically priced between $500 and $1000.

What earlier warning does this post reference, and what was it about?

The post references blueAPACHE's earlier warning about fake Australia Post emails spreading TorrentLocker, noting this new AFP-themed campaign follows the same pattern.

Source

Knowledge Base

What is the fake subpoena email scam described in blueAPACHE's blog post?

The scam is a ransomware email pretending to be from the Australian Federal Police (AFP). It is branded with the AFP logo, uses the subject line "AFP You have been issued", and claims the recipient has been subpoenaed to appear in court due to a "law violation," including a fake case number and date.

Has the AFP confirmed whether it sends subpoenas via email?

Yes. The AFP advised that it was aware of the fake email and made a statement confirming that it does not issue subpoenas via email.

What were the warning signs that the AFP subpoena email was fake?

The email's "from" address (tom@padeldanmark.dk) originated from Denmark rather than the AFP, and the email included an unsubscribe option, which is unusual for a supposed legal subpoena.

What happens if you click the links in the fake AFP subpoena email?

The links (a text link and a button) take you to a fake AFP website requiring completion of a captcha form to access supposed case details. Completing the captcha results in downloading a zip file that appears to contain court details but actually contains the TorrentLocker ransomware.

What does the TorrentLocker ransomware do once it is opened?

TorrentLocker typically attempts to delete volume shadow copies to prevent file recovery, copies itself to the Windows directory, and contacts a command and control server. It then generates an encryption key, encrypts all accessible files on the network, displays a ransom message, and sends details of the encrypted files to the command and control server. It also harvests email accounts from email programs (including online accounts) and sends them to the command and control server to further spread the malware.

How is ransom typically paid for TorrentLocker, and what happens if payment is delayed?

Payment is made with bitcoins. TorrentLocker offers a reduced fee if payment is made within a short period (usually four days), after which the price doubles. It is claimed that after one month the decryption key is destroyed and encrypted files become unrecoverable.

How much does the TorrentLocker decryption typically cost, and is payment guaranteed to work?

The decryption file is typically priced between $500 and $1000. Even after paying, there is no guarantee of receiving a working decryption key.

What should you do if you receive a suspicious subpoena-style email?

According to blueAPACHE, you should phone the issuing body for clarification before clicking on any links. If the email is identified as fake or you remain concerned, delete it (and permanently delete it from your deleted items folder or bin), and do not click on links or reply to the email.

What steps should you take to verify a subpoena email according to broader guidance?

You should not assume the email is legitimate, contact the issuing authority directly using contact information from official sources (not the email itself), verify the sender's identity through independent channels, check for signs of fraud such as poor formatting or urgent language, and consult a lawyer before responding to any legal demand.

What should you do if a genuine subpoena relates to data or services used through blueAPACHE?

You should notify blueAPACHE immediately under the terms of your service agreement, provide prompt notice, and comply with any regulatory notices or directions as required. Under blueAPACHE's General Terms and Conditions, customers are responsible for promptly notifying blueAPACHE if they receive regulatory notices, including take-down notices or legal demands, relating to their data.

Who can businesses contact for help with security concerns or staff security training related to this type of threat?

Businesses with concerns about their security posture, who want staff security training, or who want to better understand how to protect their business can contact the blueAPACHE account team.

When was blueAPACHE's warning about the fake AFP subpoena email published?

The article was published on March 8, 2016, and is written by blueAPACHE.

Images on This Page