An Iranian developer is advertising on Telegram a Ransomware-as-a-Service called BlackRouter. The same expert advertises other malware and is believed to the author of another ransomware called Blackheart.
promotes other infections such as a RAT.
BlackRouter was first observed in May 2018, at the time experts at TrendMicro discovered legitimate application AnyDesk bundled with the Ransomware.
According to Bleeping Computer, security researcher Petrovic discovered a new variant of the BlackRouter Ransomware in January, but the MalwareHunterTeam stated that only differences between this variant and previous ones were an improved GUI and the implementation of a timer.
#Ransomware #BlackRouter
— Petrovic (@petrovic082) January 6, 2019
ext.: .BlackRouter
1f15a3e297b9017c40276ad1c32d606c8beebbf432227b47360f3674bfb60127@malwrhunterteam @demonslay335 pic.twitter.com/8DKd0a9q9J
A researcher that goes online with the handle A Shadow told BleepingComputer that the same ransomware was offered as a RaaS platform in a hacking channel on Telegram by an Iranian developer.
The developer offers to its customers 80% of paid ransom payments, keeping for him the remaining 20%.
At the time, the BlackRouter was not widespread, Bleeping Computer reports only one submission to ID Ransomware since December 31.
The
[adrotate banner=”9″] | [adrotate banner=”12″] |
(
[adrotate banner=”5″] [adrotate banner=”13″]