Evil Corp, one of the biggest malware operations on the internet, has slowly returned to life after several of its members were charged by the US Department of Justice in December 2019.
In a report shared with
ZDNet today,
Fox-IT, a division within the NCC Group, has detailed the group's latest activities following the DOJ charges. [....]
Fox-IT says it named this new ransomware WastedLocker based on the file extension it adds to encrypted files, usually consisting of the victim's name and the string "wasted."
Security researchers say that an analysis of this new ransomware has revealed little code reuse or code similarities between BitPaymer and WastedLocker; however, some similarities still remain in the ransom note text.
In an interview with
ZDNet earlier today, Fox-IT says they've been tracking the use of this new ransomware family since May 2020. They say the ransomware has been exclusively deployed against US companies.
"Ransom demands that are asked by Evil Corp are now typically into the millions," Maarten van Dantzig, Fox-IT security researcher, told
ZDNet today.
"We've seen demands of more than $10 million," he added.