TorrentFreak

The place where breaking news, BitTorrent and copyright collide

Malware Extorts Cash From BitTorrent Users

A new type of malware is riding the wave of file-sharing pre-settlement letters by infecting BitTorrent users’ machines and then demanding payments in order to make imaginary lawsuits go away. ICPP Foundation try to give the impression they are RIAA and MPAA affiliated but the whole thing is a scam to extort cash and obtain credit card details.

ICCP Foundation claims to be an international company operating out of Switzerland. They say they are “committed to promoting the cultural and economic benefits of copyright” while assisting their partners to fight “copyright theft around the world”.

In fact what they really do is operate a scam to extort money from BitTorrent users.

Right at this moment we are unsure of the exact route of infection, but somehow malware (probably in either fake file or attached virus form) is displaying a “copyright violation alert” on the victim’s screen, locking it, and redirecting users to the ICPP site where they are told they have been caught infringing copyright.

There they are warned their offenses could result in 5 years in prison and a $250,000 fine and are given the option to take the (fake) case to court. They are also offered a chance to make the whole thing go away for the payment of a ‘fine’ of around $400. Victims are also prompted to give their name, address and full credit card details – it is unclear how this information is further abused but it doesn’t look good.

If they select the court option, they are scared with this screen:

So that that this evil software (believed to be located at C:\Documents and Settings\Administrator\Application Data\IQManager\iqmanager.exe) more accurately targets BitTorrent users rather than just random users, it appears to scan the user’s hard drive for .torrent files and displays these as ‘evidence’ of an earlier infringement.

In order to boost their credibility, icpp-online.com claim to be affiliated with influential partners – the RIAA, MPAA, and The Copyright Alliance. Of course, this is a complete fabrication.

This whole approach seems very similar to that employed by so-called ‘rogue software‘ or ‘scareware’ which attempt to frighten users into parting with cash for often useless software. And it seems the links to malware don’t stop there.

A WHOIS on the ICPP-Online domain reveals some contact data which shows up elsewhere in connection to other questionable activities.

Details on this new threat are scarce at the moment, so if any readers can discover more about this malware or the operation behind it, please collate the information and send it over to tips@torrentfreak.com.

Related Posts

Previous Post | Next Post

  • Mediaget
  • Download Torrents with BTguard

NewsBits

The latest news from around the web, not covered on the frontpage

  • Russia’s Largest BitTorrent Tracker Under Huge DDoS Attack

    RUTracker, Russia’s largest BitTorrent tracker, has been dealing with the effects of a DDoS attack over...

  • Reddit and WordPress Urge Congress to Shelve SOPA/PIPA

    A coalition of 70 groups, including Reddit and WordPress, are asking Congress to stop working on...

  • Turbobit.net Blocks US Visitors After MegaUpload Shutdown

    In the aftermath of the MegaUpload shutdown, file-hosting sites continue to change their services. After Uploaded.to,...

  • QuickSilverScreen Streaming Links Site Calls It Quits

    In the wake of the Megaupload raids and attacks on domains in the US and elsewhere,...

  • The Best BTjunkie Alternatives

    A few hours ago BTjunkie decided to voluntarily shut down its website. While the owners were...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

RecommendedArticles

A selection of some TorrentFreak's classics dug up from our archives.