Security News New Shifr RaaS Lets Any Dummy Enter the Ransomware Business

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
...some quotes from the article:

...
..
...
The rise and simplification of RaaS offerings
Overall, Shifr was one of the easiest to use RaaS portals that Bleeping Computer has encountered in the past year. The trend for RaaS seems to be going away from secluded communities and secret forums to open websites providing anyone with access.
In a report released today that details ransomware evolution in the past year, Kaspersky Labs experts also saw a similar rise and proliferation of RaaS portals.
Kaspersky also noted a rise of 11.4% in the number of ransomware victims from April 2016 and March 2017, compared to the previous year.

...
..
...

Several security researchers have spotted a new Ransomware-as-a-Service (RaaS) portal over the weekend that lets anyone generate their own ransomware executable just by filling in three form fields and pressing a button.

The entry level for this new ransomware is hilariously low, compared to similar RaaS portals we've seen in the past.

The ransomware generated through this service is written in Go. We've called it Shifr based on the extension it adds to encrypted files, but G Data security researcher Karsten Hahn has told Bleeping Computer that an initial analysis of this new threat reveals clues that Shifr might be related to Trojan.Encoder.6491, the first ever ransomware written in Go, discovered last year by Dr.Web security researchers.

Shifr offered through RaaS portal on the Dark Web

To obtain a copy of this ransomware, you need to visit a website on the Dark Web and have your Bitcoin address nearby.

A potential customer needs to enter this Bitcoin address, and the size of the ransom demand Shifr should ask from victims. After this, all that's left is for the user to solve a mundane CAPTCHA challenge and press a button.
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
Wow, that's crazy. but a recipe for disaster for sure. When the feds show up at their door is often the only time some of them
will have that all important "second thought" a little late by then though lol
Cool share Laser :)
 
  • Like
Reactions: LASER_oneXM

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
I guess it's more profitable to offer ready-to-go ransomware to people than spread the ransomware itself.
 
  • Like
Reactions: LASER_oneXM

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top