Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

PrisonLocker Ransomware an ‘Evolution’ From CryptoLocker

Security researchers with Malware Must Die have been tracking a sophisticated new piece of ransomware that may soon be ready to be released into the wild.

Security researchers with Malware Must Die have been tracking a sophisticated new piece of ransomware that may soon be ready to be released into the wild.

Originally called PrisonLocker but also known as PowerLocker, the malware has been apparently under development for several months and has been promoted in various hacker forums as well as publicly on Pastebin. Written in C/C++, the malware’s author says that it will encrypt virtually every file on infected machines – except .exe, .sys, .dll and other system files – via Blowfish. The uniquely generated Blowfish key is then encrypted with RSA-2048 encryption. The ransomware also encrypts files on shared drives, and detects virtual machine, debugger and sandbox environments.

“You can either approve or deny (resetting the removal clock duration, specified by you during purchase) a payment code, and then unlock/decrypt files on the PC (identified by IP),” according to an announcement of the malware posted on Pastebin.

Calling the malware a natural evolution from CryptoLocker, Bit9 CTO Harry Sverdlove said that he expects more ransomware to be on the horizon in 2014.

Advertisement. Scroll to continue reading.

“Based on the successes and failures of its predecessors, PrisonLocker appears to use more efficient methods of deterring security analysts and threat researchers, such as virtual machine/sandbox detection and more comprehensive disabling of user interaction,” he said. “The techniques used by these types of ransomware attacks are well documented and not necessarily advanced, but they are unfortunately very effective.”

The malware author claims to be willing to sell the malware for about $100 per license. In an ironic twist, Malware Must Die said they were able to tie the malware’s author to a Twitter account @Wenhsl and the security blog Wenhsl[dot]blogspot.com. In the Twitter profile, the user describes himself as an “infosec/malware researcher.”

Andrew Meyer, vice president of intelligence services at CrowdStrike, speculated that the person may have a foot in two worlds – the white hat world and the black hat world.

“He’s probably seeing that being a legitimate security researcher was not as financially-motivating or beneficial as he hoped it might have been, so maybe he’s starting to look into other options,” he said.

He added that posting details of the malware to a public forum was not a smart idea.

“This is not somebody…I would say was maybe as good a criminal as he was a coder perhaps because his operational security was just terrible,” he said.

Malware Must Die urged law enforcement to take a look at the information that has been gathered on the case and the suspect.

“Most malware authors are no different than everyone else – they follow trends that have proven to be successful,” said Sverdlove. “CryptoLocker has garnered a lot of press lately and has been very lucrative for the criminals. That’s a two-for-one win: the attackers get both money and glory, appealing to both criminals and hackers alike. It is inevitable that copycats and variants will follow. CryptoLocker has shown everyone how effective and profitable [ransomware] can be without much effort.”

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Malware & Threats

Unpatched and unprotected VMware ESXi servers worldwide have been targeted in a ransomware attack exploiting a vulnerability patched in 2021.

Malware & Threats

Cisco is warning of a zero-day vulnerability in Cisco ASA and FTD that can be exploited remotely, without authentication, in brute force attacks.