This fake copyright scam is infecting PCs with ransomware — what to know

Man looking at a locked computer
(Image credit: Shutterstock)

Cybercriminals have launched a new phishing campaign that uses alleged copyright violations as a means to infect the systems of unsuspecting users with ransomware.

As reported by BleepingComputer, recipients of these emails are warned that they used media files online without a license from their creator and that they must remove the content in question from their website or face legal action.

According to a blog post from the antivirus company AhnLab which first discovered the campaign, the emails themselves don’t specifically state what content was used without permission. Instead, recipients are urged to download and open an email attachment for more information.

The attachment is a password-protected ZIP file which contains an executable file disguised as a PDF. By entering the password contained in the email, unsuspecting users think they’ll find out more regarding the alleged copyright violation. However, doing so actually loads and encrypts a user’s devices with the LockBit 2.0 ransomware.

Ransomware-as-a-service model

Hand paying to unlock a system locked by ransomware

(Image credit: Shutterstock)

Unlike with other ransomware, LockBit uses a ransomware-as-a-service (RaaS) model in which cybercriminals pay for access to the malware to use in their own attacks.

In addition to earning a malware’s creator more, this business model also helps shield them from some legal risk as they aren’t personally infecting individuals and businesses with ransomware. The cybercriminals who purchase access to malware (likely on dark web hacking forums) to use in their attacks are known as affiliates.

At the same time, using an RaaS model helps expand accessibility and the potential reach of a particular ransomware strain. This is because many different cybercriminals are using the same ransomware to attack multiple targets as opposed to a single group.

When it comes to the most popular RaaS providers, LockBit is right up there with REvil, Maze, Ryuk and DarkSide. It’s also worth noting that several ransomware gangs including Maze have begun creating their own data leak sites in an attempt to coerce victims into paying their ransom demands. If a victim doesn’t pay up, their data is released publicly and available for other hackers to use in their attacks.

As copyright violation scams have become more prevalent in recent years, it’s worth keeping a close eye on your inbox to avoid falling victim to one yourself.

First off, you should always be hesitant when an email or message tries to instill a sense of urgency and use your emotions against you. If you’re worried about a potential lawsuit for misusing an image on your website or on social media, you’re more likely to click on malicious links or attachments. This is why you should try to keep your cool and carefully read over emails from unknown senders before replying, clicking on links or downloading attachments. Even then though, you should likely avoid clicking on or downloading anything from someone you don’t personally know online.

When it comes to phishing emails and other scams, spelling and grammatical errors can be a major red flag. As many cybercriminals don’t live in English-speaking countries, they are more likely to make common spelling or grammatical mistakes that a native speaker wouldn’t. Likewise, you should also examine the email address as well as the URLs of any links for spelling inaccuracies as this could be an attempt at brand impersonation.

Even if you do happen to misuse copyrighted material on social media, you’re more likely to get a copyright strike first before receiving an email informing you about possible legal action. This means that you’ll get a message on the social media platform from the company itself instead of from the actual copyright holder over email.

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
Reddit logo and Reddit logo on phone
Hackers have created hundreds of fake Reddit sites to spread info-stealing malware
An image of a CAPTCHA
Hackers are using reCAPTCHA to trick users into infecting their own PCs with malware — how to stay safe
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Tom Hiddleston as Robert Laing in "High Rise" now streaming on Netflix
5 best Netflix movies in March you haven't watched yet
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours
A TV with the Netflix logo sits behind a hand holding a remote
Netflix is rolling out a big video quality upgrade — what you need to know