Stories
Slash Boxes
Comments

SoylentNews is people

posted by hubie on Friday July 22 2022, @04:19AM   Printer-friendly
from the write-once-run-anywhere dept.

A new ransomware family dubbed Luna can be used to encrypt devices running several operating systems, including Windows, Linux, and ESXi systems.

Discovered by Kaspersky security researchers via a dark web ransomware forum ad spotted by the company's Darknet Threat Intelligence active monitoring system, Luna ransomware appears to be specifically tailored to be used only by Russian-speaking threat actors.

"The advertisement states that Luna only works with Russian-speaking affiliates. Also, the ransom note hardcoded inside the binary contains spelling mistakes. For example, it says 'a little team' instead of 'a small team'," Kaspersky said.

[...] The group behind this new ransomware developed this new strain in Rust and took advantage of its platform-agnostic nature to port it to multiple platforms with very few changes to the source code.

Using a cross-platform language also enables Luna ransomware to evade automated static code analysis attempts.

"Both the Linux and ESXi samples are compiled using the same source code with some minor changes from the Windows version. The rest of the code has no significant changes from the Windows version," the researchers added.

Luna further confirms the latest trend adopted by cybercrime gangs developing cross-platform ransomware that use languages like Rust and Golang to create malware capable of targeting multiple operating systems with little to no changes.


Original Submission

This discussion was created by hubie (1068) for logged-in users only, but now has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 3, Funny) by c0lo on Friday July 22 2022, @05:04AM (5 children)

    by c0lo (156) on Friday July 22 2022, @05:04AM (#1262242) Journal

    A good thing they didn't developed it in Java or PHP, can you imagine how insecure the ransomware would have been?

    --
    https://www.youtube.com/watch?v=aoFiw2jMy-0
    • (Score: 0) by Anonymous Coward on Friday July 22 2022, @08:10AM (2 children)

      by Anonymous Coward on Friday July 22 2022, @08:10AM (#1262254)

      Really, Java and PHP in the same bucket now? LOL!

      • (Score: 4, Interesting) by c0lo on Friday July 22 2022, @08:55AM (1 child)

        by c0lo (156) on Friday July 22 2022, @08:55AM (#1262257) Journal

        After C (which doesn't cross-run), Java and PHP programs show the most vulnerabilities [medium.com]

        --
        https://www.youtube.com/watch?v=aoFiw2jMy-0
        • (Score: 3, Insightful) by Freeman on Friday July 22 2022, @03:13PM

          by Freeman (732) Subscriber Badge on Friday July 22 2022, @03:13PM (#1262288) Journal

          That webpage hurt the eyes. Also, I wouldn't count that as an authoritative source for anything. Wikipedia is probably more authoritative than that.

          --
          Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
    • (Score: 2) by DannyB on Friday July 22 2022, @06:45PM (1 child)

      by DannyB (5839) Subscriber Badge on Friday July 22 2022, @06:45PM (#1262331) Journal

      Java and PHP are very different.

      With Java, how would you get your ransomware to target systems with enough memory to actually run them?

      --
      How often should I have my memory checked? I used to know but...
      • (Score: 3, Funny) by c0lo on Saturday July 23 2022, @12:32AM

        by c0lo (156) on Saturday July 23 2022, @12:32AM (#1262418) Journal

        You deliver some extra RAM to the owners and kindly ask them to upgrade before. One-off investment, ya know?

        --
        https://www.youtube.com/watch?v=aoFiw2jMy-0
  • (Score: 3, Interesting) by Frosty Piss on Friday July 22 2022, @05:35AM

    by Frosty Piss (4971) on Friday July 22 2022, @05:35AM (#1262247)

    Luna ransomware appears to be specifically tailored to be used only by Russian-speaking threat actors.

    So the Kaspersky folks are done using it and have moved on to something better?

  • (Score: -1, Troll) by Anonymous Coward on Friday July 22 2022, @08:40AM

    by Anonymous Coward on Friday July 22 2022, @08:40AM (#1262256)

    When you say malware, i say where are the samples, gimme one?

    Hard to say how good/bad craftsmanship is without that...

    ( ... must resist dunking on their choice of languages, cos it doesn't matter in this scenario.
    Could have written it in PHP or java or ecmascript, wouldn't make a slightest difference. )

    "mimicking Windows Services for persistence reasons" and using a distinct binary (as opposed to carefullly writing over some existing executable in ram) is signs of lower then average sophistication, but its ransomware... quality is irrelevant here, and i suppose to these.. for-profit-wankers.. dumb/simple tricks like that are expensive and eat into margin.

    What a waste of effort.

  • (Score: 1, Redundant) by iWantToKeepAnon on Saturday July 23 2022, @12:31AM

    by iWantToKeepAnon (686) Subscriber Badge on Saturday July 23 2022, @12:31AM (#1262417) Homepage Journal

    ...The rest of the code has no significant changes from the Windows version," the researchers added.

    ... capable of targeting multiple operating systems with little to no changes.

    Did this guy have a word minimum to meet?

    --
    "Happy families are all alike; every unhappy family is unhappy in its own way." -- Anna Karenina by Leo Tolstoy
(1)