Criminals caught trying to recruit insiders to plant ransomware
Employees offered cut of proceeds if they deploy DemonWare on their behalf
Security researchers have discovered a new campaign where cyber criminals offer money to a victim organization’s staff to install ransomware on their behalf.
Researchers at Abnormal Security identified several emails criminals sent to their customers soliciting their help in an insider threat scheme. The aim was for them to infect their companies’ networks with ransomware. Researchers said the emails came from someone with ties to the DemonWare ransomware group.
The latest campaign, criminals told employees they would receive $1 million in Bitcoin — 40% of the presumed $2.5 million ransom — if they deployed ransomware on a company computer or Windows server.
“The employee is told they can launch the ransomware physically or remotely. The sender provided two methods to contact them if the employee is interested—an Outlook email account and a Telegram username,” said researchers.
Crane Hassold, director of threat intelligence with Abnormal Security, said to better understand what was happening, the firm set up a fictitious persona and contacted the hackers on Telegram to see if they could get a response.
"It didn't take long for a response to come back, and the resulting conversation gave us an incredible inside look at the mindset of this threat actor."
"Based on our conversation with the actor, he claimed to have successfully deployed the ransomware against three companies; however, we haven't been able to verify his claims,” he added.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
A half-hour later, the actor responded and asked whether the researcher, posing as a prospective accomplice, could access our fake company’s Windows server. The researcher affirmed this and was then sent two links for an executable file we could download on WeTransfer or Mega.nz, two file sharing sites.
Based on an analysis of the file, researchers confirmed the files were ransomware. Further investigation confirmed the hacker was Nigerian. The hacker also claimed to have developed the DemonWare ransomware, although researchers said all code for DemonWare is freely available on GitHub.
“In this case, our actor simply needed to download the ransomware from GitHub and socially engineer someone to deploy the malware for them,” said Hassold.
RELATED RESOURCE
How to reduce the risk of phishing and ransomware
Top security concerns and tips for mitigation
Hassold said knowing the hacker is Nigerian brings the entire story full circle and provides some notable context to the tactics used in the initial email identified.
“For decades, West African scammers, primarily located in Nigeria, have perfected the use of social engineering in cyber crime activity,” Hassold said.
“While the most common cyber attack we see from Nigerian actors (and most damaging attack globally) is business email compromise (BEC), it makes sense that a Nigerian actor would fall back on using similar social engineering techniques, even when attempting to successfully deploy a more technically sophisticated attack like ransomware,” Hassold added.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Cyber resilience in the UK: learning to take the punchesColumn UK law now puts resilience at the centre of cybersecurity strategies – but is legislation simply catching up with enterprise understanding that resilience is more than just an IT issue?
-
CISPE claims European Commission gave Broadcom a ‘blank cheque to raise prices, lock-in, and squeeze customers’ with VMware dealNews Cloud providers have issued a formal response to the General Court of the European Union after the Commission defended its approval of the deal
-
15-year-old revealed as key player in Scattered LAPSUS$ HuntersNews 'Rey' says he's trying to leave Scattered LAPSUS$ Hunters and is prepared to cooperate with law enforcement
-
The Scattered Lapsus$ Hunters group is targeting Zendesk customers – here’s what you need to knowNews The group appears to be infecting support and help-desk personnel with remote access trojans and other forms of malware
-
Impact of Asahi cyber attack laid bare as company confirms 1.5 million customers exposedNews No ransom has been paid, said president and group CEO Atsushi Katsuki, and the company is restoring its systems
-
The US, UK, and Australia just imposed sanctions on a Russian cyber crime group – 'we are exposing their dark networks and going after those responsible'News Media Land offers 'bulletproof' hosting services used for ransomware and DDoS attacks around the world
-
A notorious ransomware group is spreading fake Microsoft Teams ads to snare victimsNews The Rhysida ransomware group is leveraging Trusted Signing from Microsoft to lend plausibility to its activities
-
Volkswagen confirms security ‘incident’ amid ransomware breach claimsNews Volkswagen has confirmed a security "incident" has occurred, but insists no IT systems have been compromised.
-
The number of ransomware groups rockets as new, smaller players emergeNews The good news is that the number of victims remains steady
-
Teens arrested over nursery chain Kido hacknews The ransom attack caused widespread shock when the hackers published children's personal data
