Cheap and effective ransomware-as-a-service introduced in Russian underground
Full article510 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
For those in the ransomware business, Karmen is highly professional and easy to use.
A cheap, effective and easy-to-use ransomware service is currently being sold in the Russian-language hacking underground.
At a cost of $175, Karmen allows any buyer to encrypt infected machines using the AES-256 protocol and then trigger a ransom note demanding money, according to the security firm Recorded Future.
Unlike most other ransomware, Karmen knows how to defend itself. The malware deletes its own decryptor if analysis software or a sandbox environment is detected.
Andrei Barysevich, director of advanced collection at Recorded Future said Karmen doesn’t look to be anything “groundbreaking,” but shows that customer service is becoming more and more of a selling point when it comes to malware.
“A comeback of paid variations of malware, which was almost overtaken by the ransomware-as-a-service business model in 2016, could escalate the problem for individuals and businesses even further,” Barysevich told CyberScoop. “As novice cybercriminals are getting more opportunities to engage in ransomware attacks, it is very likely to see even more disturbing news about successful infections. ”
The tool is developed by a team includes two individuals: DevBitox, a Russian-speaking cybercriminal who sells the product, and an unknown developer in Germany, according to Recorded Future.

The dashboard for Karmen users
Karmen has been observed since December 2016 when it was developed from the open source ransomware project Hidden Tear. The scope of Karmen’s infections and sales isn’t clear, but Recorded Future researchers observed at least 20 sales by DevBitox.
Here’s DevBitox’s commercial for Karmen:
https://www.youtube.com/watch?v=xUkyCyyPsdA
The ransomware is interesting and highly professional but, like most malware, not entirely secure. Most antivirus programs detect the malware. Bleeping Computer, a security blog, offers numerous options for victims to address being infected including Avast’s decryption tool.
Chris Bing contributed to this story.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/karmen-ransomware-recorded-future-russia/