Fraudulent Interpol Emails Fuel Global Ransomware Campaign

Keerthana S July 03, 2026 | 02:31 PM Technology

Cybercriminals are impersonating Interpol in a global phishing campaign that tricks small businesses into installing ransomware disguised as evidence in a fake cybercrime investigation.

The operation, uncovered by Bitdefender's Antispam Lab, has targeted organizations across Europe, Asia, the Middle East, and the United States, relying on convincing social engineering rather than highly sophisticated malware.

Fake Investigation, Real Threat

The attackers send emails claiming to come from Interpol's cybercrime investigation unit, informing recipients that authorities have uncovered evidence linking their organization to suspicious online activity.

Figure 1. Global Ransomware.

Instead of attaching the supposed evidence, the email directs victims to download a password-protected archive hosted on Proton Drive. To make the request appear legitimate, the password is conveniently included in the message itself. Once extracted, the archive appears to contain a video documenting the alleged investigation. In reality, the file is a Windows executable that silently launches ransomware on the victim's computer. Figure 1 shows global ransomware.

Malware Hidden Behind Multiple Layers

After being executed, the malware unpacks itself through several archive layers before encrypting files across available drives. Victims are then presented with a ransom note stating that their files have been locked and can only be recovered using a decryption key. Instead of demanding a fixed payment, however, the attackers instruct victims to negotiate through the encrypted messaging platform Tox.

Custom-Built Rather Than Industrialized

Bitdefender researchers say several characteristics suggest the campaign is not operated by a major ransomware-as-a-service (RaaS) group. Unlike established ransomware families, the malware lacks many advanced capabilities, relies on hardcoded encryption values, and does not direct victims to a dedicated Tor-based payment portal. Instead, the attackers simply provide a Tox chat ID for negotiations, indicating the ransomware was likely custom-built or assembled from publicly available code.

Small Businesses in the Crosshairs

Although technically less sophisticated than many modern ransomware strains, the malware can still cause significant operational disruption. The campaign has targeted organizations in industries including food and agriculture, legal services, pharmaceuticals, media, finance, and technology. According to Bitdefender, small businesses appear to be the primary targets because many lack dedicated cybersecurity teams and formal procedures for verifying unexpected communications from law enforcement agencies.

How to Stay Protected

Security experts emphasize that legitimate law enforcement organizations do not send unsolicited emails asking recipients to download password-protected archives from cloud storage services as evidence in criminal investigations [1]. Businesses that receive such messages should verify their authenticity using official contact information before opening attachments or downloading files.

Bitdefender also recommends that any organization which may have executed the malware immediately disconnect the affected system from the network, perform a comprehensive security scan, notify its IT team or managed service provider, change important account passwords from a clean device if credential theft is suspected, and report the phishing attempt to both the email provider and the appropriate cybersecurity authorities.

The campaign serves as another reminder that convincing social engineering—not sophisticated malware alone—remains one of the most effective tools available to cybercriminals.

References
  1. https://cyberinsider.com/fake-interpol-investigation-emails-deliver-custom-ransomware-worldwide/
Cite this article:

Keerthana S (2026), Fraudulent Interpol Emails Fuel Global Ransomware Campaign, AnaTechMaz, pp.279.

Recent Post

Blog Archive