Amateurish DemonWare Ransomware Campaign Recruits Company Workers as Affiliates

ProLock Partners With Qakbot

The DemonWare Ransomware is a simple project whose creator has made it available on their GitHub page. They state that the DemonWare implant should not be used with malicious intent. Instead, developers can use it for testing and educational purposes. Unfortunately, such disclaimers cannot stop cybercriminals from stealing projects and using them for their evil deeds. This is exactly the faith of the DemonWare Ransomware. Thanks to being open-source, hackers can make slight changes to its code to edit it according to their needs. This enables them to use a different ransom note, perform extra tasks, or simply change the file extension that the DemonWare Ransomware uses to mark files it locks.

The default version of the DemonWare Ransomware marks files with the '.DEMON' extension and drops the document 'README.txt.' The latter explains ransomware attacks to the victim and tells them that they would typically be asked to pay a ransom fee to recover their data. However, since the DemonWare Ransomware is educational, the original author does not ask for money. They refer the user to a website, where they will be able to get their unique decryption key for free.

Amateur Hackers Adopt DemonWare Ransomware, Trying to Recruit Affiliates

However, cybercriminals do not care about disclaimers, and this is DemonWare Ransomware's faith. One of the latest threat actors to make use of this malware also seems to use a peculiar method to find affiliates. The perpetrators certainly seem to be amateurs considering that they are using the first open-source ransomware they found on GitHub. They are approaching employees of companies and ask them to become a part of their scheme. The recipient can do this by planting the ransomware on the company network and then net 40% of the ransom fee that may be paid eventually. Allegedly, the criminals plan to ask for over a million dollars, so the scheme can be very lucrative. The crooks use the email cryptonation92@oulook.com and the Telegram madalin8888.

You can rest assured that the offer is not a good option. Not only will people be criminally prosecuted for planting ransomware, but it is unlikely that the amateurish perpetrators will pay out any money. If you receive an email from the alleged creators of the DemonWare Ransomware, you should ignore it.

August 20, 2021
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.