ORX-Locker, a Web Platform to Create Ransomware
LevelBlue Completes Acquisition of Cybereason. Learn more
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
LevelBlue Completes Acquisition of Cybereason. Learn more
The only thing more dangerous than cryptolocker-type ransomware in the hands of a highly skilled hacker is the same ransomware offered as a service and made available to the general public. Similar to the private TOX RaaS (Ransomware as a Service) platform discovered in August, ORX-Locker is a free-to-use web platform where anyone can create and download malware that will encrypt a victim’s file system and demand payment for recovery. This is one of the first public RaaS sites we’ve seen, with the majority of them discovered in the past private and/or requiring approval of new members.
The sign up process for ORX-Locker is completely anonymous (no email required) and the site will generate a custom malware executable for anyone, at no charge. Like TOX, they collect a percentage on the backend when victims remit payment and allow you to set your own ransom amount. This puts malware development, traditionally requiring the specialized skill of writing code, in the hands of anyone with the motivation to do wrong. While the delivery of the payloads is still something the attacker is responsible for, that requires a much lower technical prowess that the authoring of ransomware. Even in the event that the attacker has absolutely no experience whatsoever with computing other than web browsing, there are plenty of sites that facilitate or even perform the payload delivery for them.
LevelBlue Labs continues to perform cutting edge research on threats like these, collecting large amounts of data and then analyzing it to extrapolate expert threat intelligence. The Labs team has already released IDS signatures and a correlation rule to the AlienVault Unified Security Management (USM) platform so customers can identify activity related to this exploit:
For further investigation into ORX-Locker and its ransomware development platform, visit the Open Threat Exchange (OTX) and see what research members of the community have done:
LevelBlue is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.