6 ms·
Ransomware as a Service
- karrotwaltz 9y ago> The business model behind the service is simple: the bad guys keep 10% of the ransom. Creating a ransomware is indeed not a very nice thing to do, but IMO the ones that deserve the most to be called "bad guys" are the ones that actually spread the binary (so, the ones that keep the other 90%)
- philipov 9y agoThey're all bad guys, brent.
- ghostbrainalpha 9y agoNooooooo........ We just like the marching, and the boots, and the hats.
- jacquesm 9y agoI'm ok with calling them both bad guys.
- ourmandave 9y agoSo, like an arms dealer that will sell to anyone?
- cocoa19 9y agoI was thinking of that analogy as well. With weapons, you can claim it is for self defense. I guess some people will argue that releasing ransomware will make software developers study the different types of attacks, so they increase security in computer systems.
- Retra 9y agoThey do increase security... but if violating security could be justified like that, then why have any security at all? You'd already have a useful justification for legitimately violating security. Like if drinking poison builds up immunity, you don't get a free pass to feed people poison because of it. If you did, then the immunity goal doesn't matter because everyone would be poisoned to death first.
- sorokod 9y agoand if push comes to shove mention that offence is the best defence.
- blauditore 9y agoI find it somewhat ironic they include a captcha to protect against malicious users.
- moate 9y agoDon't want to wind up in an Xzibit moment. "Yo dog, we heard you like ransomware, so we put ransomware in your ransomware so we can steal when you steal!"
- TomK32 9y agoThat's probably where the real money is to be made...
- nercht12 9y agoWhen you're evil, the first thing you lose is trust in everyone else. After all, if you can stab in the back, what stops others from stabbing you?
- johnnycarcin 9y ago> "Based on the strings present in the PE file, it has been written in Go" I find this kind of interesting. I've seen reports on other malware/virus stuff written in Go recently. I wonder if this is because the ability to cross compile with Go is pretty painless? Or is it because the language is fairly approachable but still allows you to dig a bit "deeper" if you need to?
- nothrabannosir 9y agoMaybe it’s a social reason and not a technical one… like, maybe Go is more popular in… some… country… and maybe that country happens to be over represented in… I mean, obviously not. Of course. But maybe…
- sincerely 9y agoThis sort of comment is pretty frustrating for people who don't already know what you're talking about. What are you trying to say?
- dmm 9y agohttps://trends.google.com/trends/explore?q=golang#GEO_MAP https://trends.google.com/trends/explore?q=golang#GEO_MAP
- johnnycarcin 9y agoThat is very interesting, thanks for providing the link.
- ikeboy 9y ago>Communications with the C2 server are performed via HTTPS: kdvm5fd6tn6jsbwh[.]onion[.]to (185[.]100[.]85[.]150) located in Romania. That's just a tor tunnel, IP and location doesn't matter.
- colonelxc 9y agoThey also posted a bunch of hashes for a file which was customized for them, and then remarked that virustotal hadn't seen it. Though it does make me think that it would be a good trick to offer this 'service', but then keep all the proceeds (everyone gets the same ransomware download). Maybe less profitable on the long term though.
- slig 9y ago> They also posted a bunch of hashes for a file which was customized for them, and then remarked that virustotal hadn't seen it. Surely antivirus are not just trying to match the SHA1 of executables with SHA1 of known virus/malware, otherwise it would be trivial to bypass them.
- itsnotlupus 9y agoThey used to do a lot of fancy things, back in the days, including running bits of suspicious executables in heavily sandboxed interpreters to spot behavioral patterns. I'm guessing those kind of approaches have largely gone away, being replaced with signatures that are hopefully fuzzier than a wholesale cryptographic hash, but still essentially only catching things after the fact, which works well with subscription business models.
- csteegz 9y agoNo, AV has capabilities much more sophisticated then that, however from what I understand, within the malware analysis community specific samples are generally identified with their hash. In addition, if the hash of a file is known-bad, you can skip all the binary pattern matching and heuristics and stuff.
- 9y ago
- btx 9y agoInterestingly it does not seem to be a new concept: https://www.reddit.com/r/netsec/comments/37ko5v/introducing_raas_ransomware_as_a_service/ https://www.reddit.com/r/netsec/comments/37ko5v/introducing_... https://securingtomorrow.mcafee.com/mcafee-labs/meet-tox-ransomware-for-the-rest-of-us https://securingtomorrow.mcafee.com/mcafee-labs/meet-tox-ran... They used to take 20% 'commission'.
- JumpCrisscross 9y agoI'm waiting for something like this to take the form of an Ethereum smart contract.
- hellbanner 9y agoYes. Automated trading is going to bring about many terrifying things, unfortunately.