Ransomware-as-a-Service Starter Pack Has Been Discovered

While ransomware attacks aren’t for the faint of heart, ransomware-as-a-service helps even the least experienced cybercriminal reach a new low.

Cybercrimes and ransomware have pushed their way through the marketplace, paving their way to make some quick cash (well, Bitcoin, technically…). Ransomware is a type of malicious software that locks files and only decrypts them in exchange for a ransom. Most strains of ransomware are deployed by professional criminals. Ransomware-as-a-service (RaaS), however, can be purchased and deployed by an amateur.

For only $175, you can purchase a custom ransomware dubbed Karmen. This ransomware allows them to remotely control the ransomware from their own web browser, meaning the amateur-attacker can see a centralized web dashboard of the ransomware campaign. They can monitor their victims’ computers and up their ransom, if needed.

This “starter-pack” for attackers allows them to set up their own infrastructure and includes a PHP server that runs a MySQL database.

According to zdnet.com, “DevBitox has also reportedly adapted the open-source malware to include a built-in defense mechanism that detects if the ransomware is run inside a virtual machine, or whether debuggers and analyzing software are found on the system. This then triggers an automatic deletion of the decryptor -- essentially nuking any chance of getting any locked files back.”

As part of this package, the purchaser receives “support” for the ransomware-infecting process. They’ll receive up to three file cleanings, a full software package (which includes the web dashboard and malware), as well as a 12-kilobyte file that is meant to be attached to an email.

Attackers can make a pretty penny off of locking files of those who were unsuspecting; that goes for even the least experienced one in the bunch. However, if your files are backed up, you can always reevert back to an earlier point in time…

