WastedLocker Ransomware Giacomo Lanzi

WastedLocker: Next generation ransomware

WastedLocker is ransomware attack software that began targeting businesses and other organizations in May 2020. It is known for its high ransom demands reaching millions of dollars per victim. It is the product of a group of highly skilled cyber criminals who have been operating for over a decade: Evil Corp.

Who is behind WastedLocker Ransomware

The group behind WastedLocker goes by the name of Evil Corp and some of the individuals associated with it have a long history in the world of cybercrime. The group is best known for managing the Dridex malware and botnet since 2011, but has also been responsible for creating ransomware programs over the years.

Through various episodes of criminal attacks, the group has been developing malware targeting mainly US companies since 2011. For this reason they have been known to the police for some time. After a period of inactivity, the group reappeared in January 2020 and their activity resumed as usual, with victims appearing in the same regions as before.

WastedLocker is a completely new program from Evil Corp that began infecting organizations in May 2020. It does not share the code with BitPaymer (a previously used software) but shows other similarities in the ransom note and per-victim customization. Evil Corp’s lack of activity between March and May could be explained by the group that was working on developing this new cyber threat as well as other tools that make up its toolset.

WastedLocker Hacker

How does it work

According to Symantec reports, the infection chain for WastedLocker starts with a JavaScript-based attack framework. The framework, called SocGholish, is distributed as a fake browser update from warnings displayed on legitimate but compromised websites. Hacked news websites are a common vector.

The SocGholish framework is distributed as a ZIP file. Once opened and executed, it initiates a chain of attacks that involves downloading and running PowerShell scripts and the Cobalt Strike backdoor. Evil Corp has used this same distribution technique in the past to distribute the Dridex Trojan, so it has been part of its arsenal for a long time.

Once hackers gain access to a computer, they begin distributing various tools to steal user credentials. In addition, they can also increase privileges and perform a lateral movement to other machines. The attackers’ goal is to identify and gain access to high-value systems such as servers. They then implement an ad hoc binary file on the compromised machines for the victims.

The use of manual hacking and system administration tools are part of a trend observed in recent years. According to this trend, cybercriminals are increasingly adopting attack techniques that in the past were associated with cyber espionage. This trend poses a serious problem for smaller organizations that lack the budget and IT resources to deploy defenses against advanced threats, but are a frequent target for ransomware groups and other financially motivated cybercriminals.

WestedLocker in detail

WastedLocker uses a combination of AES and RSA encryption in its encryption routine which is similar to other ransomware programs. Each file is encrypted with a unique 256-bit AES key generated on-the-fly. These AES keys along with other information about the encrypted files are then encrypted with a 4096-bit public RSA key which is encoded in the WastedLocker binary. Attackers keep the private part of the RSA key pair needed to retrieve AES keys and decrypt individual files.

According to an analysis by Kaspersky Lab, the encryption routine is strong and correctly implemented. So the victims cannot recover their files without the attacker’s private RSA key. Because it is a manually distributed ransomware threat customized to each target, attackers generate unique RSA key pairs for each victim. I mean, the key received from one organization after paying the ransom will not work to decrypt the files of another affected organization.

Some distinctive aspects of WastedLocker

The WastedLocker ransomware has a mechanism that allows attackers to prioritize certain directories during the encryption routine. This is probably used to ensure that the most important and valuable files are encrypted first in case the encryption process is detected by the system administrators and stopped while it is in progress.

The malware appends an extension to files consisting of the victim’s name and the word “wasted”. Also, it generates a text file with the ransom note for each file, which means that each directory will contain hundreds or thousands of copies of the ransom note.

WastedLocker is designed to delete shadow copies (the default backups made by the Windows operating system) and tries to encrypt files on the network, including remote backups.

After the July 2020 attacks

The Securonix Threat Research Team (STR) is actively investigating the details of Wastedlocker ransomware critical attacks. These have reportedly already affected more than 31 companies, of which 8 are Fortune 500 companies.

Impact

Here are the key details regarding the impact of WastedLocker ransomware attacks:

WastedLocker ransomware is relatively new, used by EvilCorp, which previously used the Dridex trojan to distribute BitPaymer ransomware in attacks against government organizations and businesses in the US and Europe.

Evil Corp group is currently focusing on targeted attacks on multiple industry casualties in recent months. Garmin is one of the latest high profile victims attacked (officially confirmed by Garmin on July 27).

– The most recent ransom amount requested was $10 million and appears to be based on the victim’s financial data. Based on the available details, the ransom has probably been paid.

– To date, a mono-extortion scheme appears to have been used, ie with only encryption and no or minimal data loss.

WastedLocker hacker

How to defend yourself

Following the analysis of the attacks and the data available, we want to suggest methods of mitigation and prevention of attacks.

– Review the backup retention policies. Make sure these are stored in a location that cannot be accessed / encrypted by the operator who placed the targeted ransomware. For example, consider write-only remote backup.

Implement a training program on the safety of end users (company employees). Since end users are the targets of ransomware, it is best that they are aware of the current risks. It is important that they are aware of the threat of ransomware and how it occurs.

Patches of infrastructure operating systems, software and firmware. Consider the possibility of leveraging a centralized patch management system.

Maintain regular, air-gaped backups of critical company / infrastructure data. An air-gaped backup and recovery strategy means making sure that at least one copy of your organization’s data is offline and not accessible from any network.

Implement security monitoring, particularly for high-value targets, to detect in advance any malicious ransomware operator positioning activity.

As always, we at SOD are available for advice and to suggest you which services you can implement for the safety of your company. Contact us to find out how we can help you keep your business defenses high.

Useful links:

 

The most dangerous Ransomware in 2020

Secure Online Desktop – Company

Critical ransomware: examples of successful attacks

 

Contact us

Share


RSS

More Articles…

Categories …

Tags

RSS Dark Reading:

RSS Full Disclosure

  • Backdoor.Win32.Zombam.gen / Information Disclosure June 15, 2021
    Posted by malvuln on Jun 15Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/ff6516c881dee555b0cd253408b64404_D.txt Contact: malvuln13 () gmail com Media: twitter.com/malvuln Threat: Backdoor.Win32.Zombam.gen Vulnerability: Information Disclosure Description: Zombam malware listens on TCP port 80 and deploys an unsecured HTML Web UI for basic remote administration capability. Third-party attackers who can reach an infected...
  • Backdoor.Win32.VB.pld / Unauthenticated Remote Command Execution June 15, 2021
    Posted by malvuln on Jun 15Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/6ff35087d789f7aca6c0e3396984894e_B.txt Contact: malvuln13 () gmail com Media: twitter.com/malvuln Threat: Backdoor.Win32.VB.pld Vulnerability: Unauthenticated Remote Command Execution Description: The malware listens on TCP port 4000. Third-party attackers who can reach infected systems can connect to port 4000 and run commands made available […]
  • Backdoor.Win32.VB.pld / Insecure Transit June 15, 2021
    Posted by malvuln on Jun 15Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/6ff35087d789f7aca6c0e3396984894e.txt Contact: malvuln13 () gmail com Media: twitter.com/malvuln Threat: Backdoor.Win32.VB.pld Vulnerability: Insecure Transit Description: The malware listens on TCP port 4000 and has a chat feature "Hnadle-X Pro V1.0 Text Chat". Messages are passed in unencrypted plaintext across the network. […]
  • popo2, kernel/tun driver bufferoverflow. June 15, 2021
    Posted by KJ Jung on Jun 15Linux kernel 5.4 version. latest. __tun_chr_ioctl function of ~/drivers/net/tun.c has a stack buffer overflow vulnerability. it get's arg, ifreq_len, and copy the arg(argp) to ifr(ifreq struct) and this steps are no bounds-checking. if cmd == TUNSETIFF or TUNSETQUEUE or and so on condition then it's enter copy_from_user function area.
  • Onapsis Security Advisory 2021-0014: Missing authorization check in SAP Solution Manager LM-SERVICE Component SP 11 PL 2 June 14, 2021
    Posted by Onapsis Research via Fulldisclosure on Jun 14# Onapsis Security Advisory 2021-0014: Missing authorization check in SAP Solution Manager LM-SERVICE Component SP 11 PL 2 ## Impact on Business Due to a missing authorization check in SAP Solution Manager LM-SERVICE component a remote authenticated attacker could be able to execute privileged actions in the […]
  • Onapsis Security Advisory 2021-0013: [CVE-2020-26829] - Missing Authentication Check In SAP NetWeaver AS JAVA P2P Cluster communication June 14, 2021
    Posted by Onapsis Research via Fulldisclosure on Jun 14# Onapsis Security Advisory 2021-0013: [CVE-2020-26829] - Missing Authentication Check In SAP NetWeaver AS JAVA P2P Cluster communication ## Impact on Business A malicious unauthenticated user could abuse the lack of authentication check on SAP Java P2P cluster communication, in order to connect to the respective TCP […]
  • Onapsis Security Advisory 2021-0012: SAP Manufacturing Integration and Intelligence lack of server side validations leads to RCE June 14, 2021
    Posted by Onapsis Research via Fulldisclosure on Jun 14# Onapsis Security Advisory 2021-0012: SAP Manufacturing Integration and Intelligence lack of server side validations leads to RCE ## Impact on Business By abusing a Code Injection in SAP MII, an authenticated user with SAP XMII Developer privileges could execute code (including OS commands) on the server. […]
  • Onapsis Security Advisory 2021-0011 Missing authorization check in SolMan End-User Experience Monitoring June 14, 2021
    Posted by Onapsis Research via Fulldisclosure on Jun 14# Onapsis Security Advisory 2021-0011: Missing authorization check in SolMan End-User Experience Monitoring ## Impact on Business Any authenticated user of the Solution Manager is able to craft/upload and execute EEM scripts on the SMDAgents affecting its Integrity, Confidentiality and Availability. ## Advisory Information - Public Release […]
  • Onapsis Security Advisory 2021-0010: File exfiltration and DoS in SolMan End-User Experience Monitoring June 14, 2021
    Posted by Onapsis Research via Fulldisclosure on Jun 14# Onapsis Security Advisory 2021-0010: File exfiltration and DoS in SolMan End-User Experience Monitoring ## Impact on Business The End-User Experience Monitoring (EEM) application, part of the SAP Solution Manager, is vulnerable to path traversal. As a consequence, an unauthorized attacker would be able to read sensitive […]
  • Onapsis Security Advisory 2021-0009: Hard-coded Credentials in CA Introscope Enterprise Manager June 14, 2021
    Posted by Onapsis Research via Fulldisclosure on Jun 14# Onapsis Security Advisory 2021-0009: Hard-coded Credentials in CA Introscope Enterprise Manager ## Impact on Business Unauthenticated attackers can bypass the authentication if the default passwords for Admin and Guest have not been changed by the administrator. This may impact the confidentiality of the service. ## Advisory […]

Customers

Newsletter