Ransomware

Ransomware-as-a-Service – Princess Evolution Ransomware Advertised in Underground Forums

The new version of Princess Locker ransomware dubbed Princess Evolution advertised in dark web forums as a ransomware as a service (RaaS) and is looking for affiliates.

The threat actors behind the new version of ransomware pushing it through affiliate programs and the affiliate would earn 60 percent of the ransom payments and rest for malware authors.

Trend Micro researchers observed the infamous Rig exploit kit delivering the new version of the Princess Locker ransomware that originally appeared in 2016.

As advertised in the underground forums the threat actor’s spent more time in developing the Princess Evolution version.

Princess Evolution Campaign

The campaign appears to be live from July 25, it includes a Coinhive coin-mining script and the ransomware, even through if the exploit kit failed to infect the victim with ransomware the cybercriminals can earn money with cryptocurrency mining.

The Princess Evolution version works same as like as Princess Locker, it encrypts the file’s and changes to a random extension and drops with instructions that ask the user to pay 0.12 bitcoin to decrypt the files. Ransom payments handled through payment page in the Tor network.

Cybercriminals hosted the malvertisement page on a free web hosting service and added Cname records pointing to the domain they used to advertise.

Locker ransomware encrypts user file’s by using the both XOR and AES algorithms and it uses user datagram protocol (UDP) for command-and-control (C&C) communication.

Ransomware still continues to be a global threat, it’s become a billion-dollar industry that shows no signs of going away anytime soon.

Also Read

Ransomware Attack Response and Mitigation Checklist

To Top

Pin It on Pinterest

Share This