Cybercriminals that specialise in ransomware, which affects thousands of computers and mobile devices every year, are ramping up their attacks against businesses. It is here that they can get their hands on valuable information and large sums of cash. This particular kind of malware, which hijacks devices and demands a ransom for their return, has managed to conquer another kind of technology: smart TVs.
Last December, one of the first high profile incidents hit twitter – an LG model that came out in 2014 that is compatible with Google TV, a version of Android tailored to televisions, was hit by malware. Once it had infiltrated the device, the malicious software demanded a ransom of $500 dollars to unlock the screen, which simulated a warning from the Department of Justice.
The appearance of the false message would lead you to believe that it’s a version of the ransomware known as Cyber.police, also known as FLocker. Ordinarily this ransomware affects smartphones with Google’s operating system. After hijacking the device, the malware collects information from the user and the system, including contact information and the location of the device, to be sent encrypted to cybercriminals.
To avoid paying the ransom, the owner unsuccessfully attempted to restore the television set to factory values, but eventually had to resort to the manufacturer’s own services to return it to a state prior to the installation of the malware. Although his relative managed to regain control of the machine without paying any sum to the criminals, he did end up having to pay the manufacturer $340 for the service, not much less than the ransom itself.
FLocker hides away its code in the raw data files – specifically, in a file called form.html stored inside the assets folder. That little technique helps the ransomware avoid static code analysis.
Once the malware runs, it decrypts the form.html file and executes the malicious code.
Before FLocker proceeds any further, it first checks to see if the computer is running in any of the following countries: Kazakhstan, Azerbaijan, Bulgaria, Georgia, Hungary, Ukraine, Russia, Armenia, and Belarus. If it finds a match, it terminates. If not, it runs its routine after 30 minutes and starts a background service that requests device admin privileges.
The Cauthon case has not caught security experts by surprise, given that last summer a team of researchers had warned of FLocker’s activity on smart TVs. In addition to the United States, ransomware attacks have been reported on smart TVs in Japan.
LG’s post-2014 model are no longer compatible with Google TV, but rather use WebOS, an open source operating system based on Linux. However, new attacks should not be ruled out, as cybercriminals continually refine their tools, which are increasingly focused on infecting Internet of Things devices at business and in the household.
Almost all connected TV products are at a risk for malware infections. As the smart TV connects to different devices it also becomes vulnerable to potential viruses and malware, making antivirus protection essential. However, there are a limited number of antivirus suites that give security to Smart TVs. Here are some top companies offering antivirus solutions for Smart TVs.
- Avira antivirus
- AT & T Internet Security Suite by McAfee
- F-Secure
If you need advice on Cyber Security – Contact our Team HERE








