Ransomware

ShinySp1d3r RaaS platform dissected

(Adobe Stock)

BleepingComputer reports that the ShinyHunters threat operation had its upcoming ShinySp1d3r ransomware-as-a-service platform examined following an upload of its encryptor on VirusTotal.

Developed from the ground up, the ShinySp1d3r encryptor for Windows not only prevents data logging to the Windows Event Viewer and ends a hard-coded list of processes and services but also facilitates self-propagation, curbs analysis, removes Shadow Volume Copies, and encrypts files with the ChaCha20 encryption algorithm, according to a report from Coveware.

Meanwhile, ShinySp1d3r's ransom note, which has been installed in all of the encrypted devices' folders, warns victims to enter negotiations within three days to avoid public disclosure of the breach. Another CLI build with runtime configuration has already been done, while Linux and ESXi versions are on the way, noted ShinyHunters, which will be operating the RaaS operation as Scattered Lapsus$ Hunters.

"We're also working on a "lightning version" pure ASM, its like lockbit green - another windows locker variant but in pure assembly and it's pretty simple," ShinyHunters said.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds