Site navigation

Junk Gun Ransomware Infiltrates RaaS Market

Elizabeth Greenberg

,

junk gun ransomware
The cheap ransomware variant is making waves in the ransomware-as-a-service marketplace. 

Sophos X-Ops has discovered multiples of a new emergent ransomware variants proliferating across the dark web.

Junk gun ransomware, cheap independently produces and crudely constructed ransomware variants, are being used by threat actors to disrupt the traditional affiliate-based ransomware-as-a-service (RaaS) model that has dominated the ransomware racket for nearly a decade.

Instead of selling or buying ransomware to – or as – an affiliate, attackers are creating and selling unsophisticated ransomware variants for a one-time cost, which other attackers sometimes see as an opportunity to target small and medium-sized businesses (SMBs) or even individuals.

“For the past year or two, ransomware has reached a kind of homeostasis. It’s still one of the most pervasive and serious threats for businesses, but our most recent Active Adversary report found that the number of attacks has stabilised, and the RaaS racket has remained the go-to operating model for most major ransomware groups,” said Christopher Budd, director, threat research, Sophos.

“Over the past two months, however, some of the biggest players in the ransomware ecosystem have disappeared or shut down, and, in the past, we’ve also seen ransomware affiliates vent their anger over the profit-sharing scheme of RaaS. Nothing within the cybercrime world stays static forever, and these cheap versions of off-the-shelf ransomware may be the next evolution in the ransomware ecosystem—especially for lower-skilled cyber attackers simply looking to make a profit rather than a name for themselves.”

As detailed in the report, the median price for these junk gun ransomware variants on the dark web was $375 (£360), significantly cheaper than some kits for RaaS affiliates, which can cost more than $1000 (£801). The report indicates that cyber-attackers have deployed four of these variants in attacks.

While the capabilities of junk gun   ransomware vary widely, their biggest selling points are that the ransomware requires little or no supporting infrastructure to operate, and the users aren’t obligated to share their profits with the creators.

Junk gun ransomware discussions are mainly taking place primarily on English-speaking dark web forums aimed at lower-tier criminals, rather than well-established Russian-speaking forums frequented by prominent attacker groups.

These new variants offer an attractive way for newer cyber-criminals to get started in the ransomware world, and alongside the advertisements for these cheap ransomware variants, are numerous posts requesting advice and tutorials on how to get started.


Recommended reading


“These types of ransomware variants aren’t going to command the million-dollar ransoms like Clop and Lockbit but they can indeed be effective against SMBs, and for many attackers beginning their ‘careers,’ that’s enough. While the phenomenon of junk gun ransomware is still relatively new, we’ve already seen posts from their creators about their ambitions to scale their operations, and we’ve seen multiple posts from others talking about creating their own ransomware variants,” said Budd.

“More concerningly, this new ransomware threat poses a unique challenge for defenders. Because attackers are using these variants against SMBs and the ransom demands are small, most attacks are likely to go undetected and unreported. That leaves an intelligence gap for defenders, one the security community will have to fill.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data