Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

7/11/2016
05:15 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

New Ranscam Ransomware Lowers The Bar But Raises The Stakes

Cisco Talos researchers discover new variant that doesn't decrypt your files after you pay up--it has already deleted them.

Ransomware variants are multiplying like rabbits: while some are more sophisticated and tougher to combat, others are more about scamming than kidnapping. Take the new Ranscam malware discovered by Cisco’s Talos team, a low-tech but highly destructive attack that demands ransom from its victims but never returns them their files because it actually deleted them.

Ranscam isn’t the first ransomware variant to destroy files rather than return them after victims pay up—there’s AnonPop and JIGSAW, for example—but it’s a glaring example of how the ransomware scam itself is so lucrative and easy to pull off that less sophisticated attackers are jumping in the game. It’s also a cautionary tale for victims counting on getting their files back when they hand over those Bitcoins.

The lack of crypto in the attack, despite promises of decryption if the victim pays up, also demonstrates that Ranscam is nowhere near as complex or advanced as Cryptowall and other ransomware attacks, the researchers say. It’s more like its name suggests: it’s a ransomware scam to make money quickly.

"Compared to other true ransomware variants such as Cryptowall which spend a significant amount of time and effort developing new functionality and features, Ranscam appears to indicate that smaller, less-funded threat actors are joining the game, attempting to quickly get a piece of the pie," says Earl Carter, security research engineer at Cisco Talos.

It's also yet another example of why solid backups can save the day in a ransomware attack. "Ranscam further justifies the importance of ensuring that you have a sound, offline backup strategy in place rather than a sound ransom payout strategy,” the Talos team wrote in a blog post today. “Not only does having a good backup strategy in place help ensure that systems can be restored, it also ensures that attackers are no longer able to collect revenue that they can then reinvest into the future development of their criminal enterprise.”

Ranscam pushes the victim the usual ransom note upon infection, claiming to have moved the files to a “hidden, encrypted partition.” The Talos team says it dug around and found that some $278 had been paid to a wallet address provided by the attackers, but no additional transactions had occurred with it since late last month.

The attack appears to be limited, and relies mainly on using fear to solicit victims to pay the ransom. The attackers even had a few mishaps in their payment screen process, Talos found.

And the good news with Ranscam is that it isn't likely to have a long lifespan as a threat. "The payout is likely to die away quickly because of [its] bad reputation" in deleting files, notes Talos' Carter.

Cisco Talos recommends a backup solution that lets you restore an infected system to “a known-good configuration as quickly as possible.” That way, ransomware won’t be so popular and useful to attackers.

Related Content:

 

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Faye___Kane
100%
0%
Faye___Kane,
User Rank: Strategist
7/30/2016 | 6:39:16 PM
Re: Ranscams and Ransomware can go down together
 

You'd think that every business would already back up it's stuff, but nooo.

One summer, I babysat the 12 users at a small company when I discovered, to my horror, that the server had never been backed up in seven years(!)

I repeatedly begged the owner, who wore a gold slab around his neck, to buy a $100 tape drive, but he wouldn't spend the money. I finally shut up about it when he got mad at my asking.

When the sys crashed the next month, I drove home depressed. "What would an IT manager at a real company have done to prevent this?  Asked again? Paid for it himself?

The next day, I was fired because I predicted it, and everyone assumed I sabotaged the server to prove my point.

Worse, I'm sure I could have recovered the data if he had let me get near it.

THESE are the people we try so hard to protect.

 
Kelly Jackson Higgins
100%
0%
Kelly Jackson Higgins,
User Rank: Strategist
7/12/2016 | 11:29:16 AM
Re: Ranscams and Ransomware can go down together
That would be nice, wouldn't it? But the seasoned ransomware attackers aren't going anywhere until orgs of all sizes do a better job at backups so they don't have to pay, and do a better job of user awareness training.
AndrewfOP
100%
0%
AndrewfOP,
User Rank: Strategist
7/12/2016 | 11:21:18 AM
Ranscams and Ransomware can go down together
"..the good news with Ranscam is that it isn't likely to have a long lifespan as a threat..."

 Quite frankly, I would prefer Ransams can stick around long enough to drag Ransomwares down with it.  If Ransams, purported to be 'reputed' Ransomware, receive the ransoms, but fail to deliver the goods anyway, 'customers' would be wised to the idea that paying ransoms are no guarantees of getting the files back.  Only good backups and no ransoms are the best strategy against Ranscams and Ransomwares.  We can then be rid of the Ransomware pandemics.

 
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/10/2019
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Jim, stop pretending you're drowning in tickets."
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13360
PUBLISHED: 2019-07-16
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.
CVE-2019-13383
PUBLISHED: 2019-07-16
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.
CVE-2019-13603
PUBLISHED: 2019-07-16
An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that. This, in combination...
CVE-2019-13605
PUBLISHED: 2019-07-16
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to base64, and thus this is different from CVE-2019-1...
CVE-2019-13615
PUBLISHED: 2019-07-16
VideoLAN VLC media player 3.0.7.1 has a heap-based buffer over-read in mkv::demux_sys_t::FreeUnused() in modules/demux/mkv/demux.cpp when called from mkv::Open in modules/demux/mkv/mkv.cpp.