WastedLocker Ransomware Giacomo Lanzi

WastedLocker: Next generation ransomware

WastedLocker is ransomware attack software that began targeting businesses and other organizations in May 2020. It is known for its high ransom demands reaching millions of dollars per victim. It is the product of a group of highly skilled cyber criminals who have been operating for over a decade: Evil Corp.

Who is behind WastedLocker Ransomware

The group behind WastedLocker goes by the name of Evil Corp and some of the individuals associated with it have a long history in the world of cybercrime. The group is best known for managing the Dridex malware and botnet since 2011, but has also been responsible for creating ransomware programs over the years.

Through various episodes of criminal attacks, the group has been developing malware targeting mainly US companies since 2011. For this reason they have been known to the police for some time. After a period of inactivity, the group reappeared in January 2020 and their activity resumed as usual, with victims appearing in the same regions as before.

WastedLocker is a completely new program from Evil Corp that began infecting organizations in May 2020. It does not share the code with BitPaymer (a previously used software) but shows other similarities in the ransom note and per-victim customization. Evil Corp’s lack of activity between March and May could be explained by the group that was working on developing this new cyber threat as well as other tools that make up its toolset.

WastedLocker Hacker

How does it work

According to Symantec reports, the infection chain for WastedLocker starts with a JavaScript-based attack framework. The framework, called SocGholish, is distributed as a fake browser update from warnings displayed on legitimate but compromised websites. Hacked news websites are a common vector.

The SocGholish framework is distributed as a ZIP file. Once opened and executed, it initiates a chain of attacks that involves downloading and running PowerShell scripts and the Cobalt Strike backdoor. Evil Corp has used this same distribution technique in the past to distribute the Dridex Trojan, so it has been part of its arsenal for a long time.

Once hackers gain access to a computer, they begin distributing various tools to steal user credentials. In addition, they can also increase privileges and perform a lateral movement to other machines. The attackers’ goal is to identify and gain access to high-value systems such as servers. They then implement an ad hoc binary file on the compromised machines for the victims.

The use of manual hacking and system administration tools are part of a trend observed in recent years. According to this trend, cybercriminals are increasingly adopting attack techniques that in the past were associated with cyber espionage. This trend poses a serious problem for smaller organizations that lack the budget and IT resources to deploy defenses against advanced threats, but are a frequent target for ransomware groups and other financially motivated cybercriminals.

WestedLocker in detail

WastedLocker uses a combination of AES and RSA encryption in its encryption routine which is similar to other ransomware programs. Each file is encrypted with a unique 256-bit AES key generated on-the-fly. These AES keys along with other information about the encrypted files are then encrypted with a 4096-bit public RSA key which is encoded in the WastedLocker binary. Attackers keep the private part of the RSA key pair needed to retrieve AES keys and decrypt individual files.

According to an analysis by Kaspersky Lab, the encryption routine is strong and correctly implemented. So the victims cannot recover their files without the attacker’s private RSA key. Because it is a manually distributed ransomware threat customized to each target, attackers generate unique RSA key pairs for each victim. I mean, the key received from one organization after paying the ransom will not work to decrypt the files of another affected organization.

Some distinctive aspects of WastedLocker

The WastedLocker ransomware has a mechanism that allows attackers to prioritize certain directories during the encryption routine. This is probably used to ensure that the most important and valuable files are encrypted first in case the encryption process is detected by the system administrators and stopped while it is in progress.

The malware appends an extension to files consisting of the victim’s name and the word “wasted”. Also, it generates a text file with the ransom note for each file, which means that each directory will contain hundreds or thousands of copies of the ransom note.

WastedLocker is designed to delete shadow copies (the default backups made by the Windows operating system) and tries to encrypt files on the network, including remote backups.

After the July 2020 attacks

The Securonix Threat Research Team (STR) is actively investigating the details of Wastedlocker ransomware critical attacks. These have reportedly already affected more than 31 companies, of which 8 are Fortune 500 companies.

Impact

Here are the key details regarding the impact of WastedLocker ransomware attacks:

WastedLocker ransomware is relatively new, used by EvilCorp, which previously used the Dridex trojan to distribute BitPaymer ransomware in attacks against government organizations and businesses in the US and Europe.

Evil Corp group is currently focusing on targeted attacks on multiple industry casualties in recent months. Garmin is one of the latest high profile victims attacked (officially confirmed by Garmin on July 27).

– The most recent ransom amount requested was $10 million and appears to be based on the victim’s financial data. Based on the available details, the ransom has probably been paid.

– To date, a mono-extortion scheme appears to have been used, ie with only encryption and no or minimal data loss.

WastedLocker hacker

How to defend yourself

Following the analysis of the attacks and the data available, we want to suggest methods of mitigation and prevention of attacks.

– Review the backup retention policies. Make sure these are stored in a location that cannot be accessed / encrypted by the operator who placed the targeted ransomware. For example, consider write-only remote backup.

Implement a training program on the safety of end users (company employees). Since end users are the targets of ransomware, it is best that they are aware of the current risks. It is important that they are aware of the threat of ransomware and how it occurs.

Patches of infrastructure operating systems, software and firmware. Consider the possibility of leveraging a centralized patch management system.

Maintain regular, air-gaped backups of critical company / infrastructure data. An air-gaped backup and recovery strategy means making sure that at least one copy of your organization’s data is offline and not accessible from any network.

Implement security monitoring, particularly for high-value targets, to detect in advance any malicious ransomware operator positioning activity.

As always, we at SOD are available for advice and to suggest you which services you can implement for the safety of your company. Contact us to find out how we can help you keep your business defenses high.

Useful links:

 

The most dangerous Ransomware in 2020

Secure Online Desktop – Company

Critical ransomware: examples of successful attacks

 

Contact us

Share


RSS

More Articles…

Categories …

Tags

RSS darkreading

RSS Full Disclosure

  • SEC Consult SA-20241112-0 :: Multiple vulnerabilities in Siemens Energy Omnivise T3000 (CVE-2024-38876, CVE-2024-38877, CVE-2024-38878, CVE-2024-38879) November 13, 2024
    Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Nov 12SEC Consult Vulnerability Lab Security Advisory < 20241112-0 > ======================================================================= title: Multiple vulnerabilities product: Siemens Energy Omnivise T3000 vulnerable version: >=8.2 SP3 fixed version: see solution section CVE number: CVE-2024-38876, CVE-2024-38877, CVE-2024-38878, CVE-2024-38879 impact: High...
  • Security issue in the TX Text Control .NET Server for ASP.NET. November 13, 2024
    Posted by Filip Palian on Nov 12Hej, Let&apos;s keep it short ... ===== Intro ===== A "sudo make me a sandwich" security issue has been identified in the TX Text Control .NET Server for ASP.NET[1]. According to the vendor[2], "the most powerful, MS Word compatible document editor that runs in all browsers". Likely all versions […]
  • SEC Consult SA-20241107-0 :: Multiple Vulnerabilities in HASOMED Elefant and Elefant Software Updater November 10, 2024
    Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Nov 09SEC Consult Vulnerability Lab Security Advisory < 20241107-0 > ======================================================================= title: Multiple Vulnerabilities product: HASOMED Elefant and Elefant Software Updater vulnerable version:
  • Unsafe eval() in TestRail CLI November 7, 2024
    Posted by Devin Cook on Nov 06This is not a very exciting vulnerability, but I had already publicly disclosed it on GitHub at the request of the vendor. Since that report has disappeared, the link I had provided to MITRE was invalid, so here it is again. -Devin --- # Unsafe `eval()` in TestRail CLI […]
  • 4 vulnerabilities in ibmsecurity November 3, 2024
    Posted by Pierre Kim on Nov 03## Advisory Information Title: 4 vulnerabilities in ibmsecurity Advisory URL: https://pierrekim.github.io/advisories/2024-ibmsecurity.txt Blog URL: https://pierrekim.github.io/blog/2024-11-01-ibmsecurity-4-vulnerabilities.html Date published: 2024-11-01 Vendors contacted: IBM Release mode: Released CVE: CVE-2024-31871, CVE-2024-31872, CVE-2024-31873, CVE-2024-31874 ## Product description ## Vulnerability Summary Vulnerable versions:...
  • 32 vulnerabilities in IBM Security Verify Access November 3, 2024
    Posted by Pierre Kim on Nov 03## Advisory Information Title: 32 vulnerabilities in IBM Security Verify Access Advisory URL: https://pierrekim.github.io/advisories/2024-ibm-security-verify-access.txt Blog URL: https://pierrekim.github.io/blog/2024-11-01-ibm-security-verify-access-32-vulnerabilities.html Date published: 2024-11-01 Vendors contacted: IBM Release mode: Released CVE: CVE-2022-2068, CVE-2023-30997, CVE-2023-30998, CVE-2023-31001, CVE-2023-31004, CVE-2023-31005,...
  • xlibre Xnest security advisory & bugfix releases October 31, 2024
    Posted by Enrico Weigelt, metux IT consult on Oct 31XLibre project security advisory --------------------------------- As Xlibre Xnest is based on Xorg, it is affected by some security issues which recently became known in Xorg: CVE-2024-9632: can be triggered by providing a modified bitmap to the X.Org server. CVE-2024-9632: Heap-based buffer overflow privilege escalation in _XkbSetCompatMap […]
  • APPLE-SA-10-29-2024-1 Safari 18.1 October 31, 2024
    Posted by Apple Product Security via Fulldisclosure on Oct 31APPLE-SA-10-29-2024-1 Safari 18.1 Safari 18.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/121571. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Safari Downloads Available for: macOS Ventura and macOS Sonoma Impact: An […]
  • SEC Consult SA-20241030-0 :: Query Filter Injection in Ping Identity PingIDM (formerly known as ForgeRock Identity Management) (CVE-2024-23600) October 31, 2024
    Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 31SEC Consult Vulnerability Lab Security Advisory < 20241030-0 > ======================================================================= title: Query Filter Injection product: Ping Identity PingIDM (formerly known as ForgeRock Identity Management) vulnerable version: v7.0.0 - v7.5.0 (and older unsupported versions) fixed version: various patches; v8.0 CVE number:...
  • SEC Consult SA-20241023-0 :: Authenticated Remote Code Execution in Multiple Xerox printers (CVE-2024-6333) October 29, 2024
    Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 28SEC Consult Vulnerability Lab Security Advisory < 20241023-0 > ======================================================================= title: Authenticated Remote Code Execution product: Multiple Xerox printers (EC80xx, AltaLink, VersaLink, WorkCentre)  vulnerable version: see vulnerable versions below fixed version: see solution section below CVE number: CVE-2024-6333...

Customers

Newsletter

{subscription_form_1}