A ransomware variant that first appeared two months ago has built a name for itself with constant updates, improved functionality, and the inability to come up with a suitable encryption algorithm that Emsisoft's Fabian Wosar couldn't crack.Called Apocalypse, the ransomware stands out from other similar tools because it uses a manual distribution method, relying on its creators to brute-force unsecured RDP (Remote Desktop Protocol) servers and install Apocalypse manually.
Fox-IT experts had warned in early May about the increase in RDP brute-force attacks specifically targeting ransomware. Apocalypse first appeared about a week after that report came out.
Before Apocalypse, malware analysts also discovered new versions of the older Bucbi ransomware, which also used RDP brute-force attacks to spread across corporate networks.
As for Apocalypse, the ransomware uses a simplistic XOR-based encryption algorithm, which is why Emsisoft's Fabian Wosar managed to crack it earlier this month and then offer a free decrypter that can unlock files without paying the ransom.
The authors of Apocalypse compensated for the situation by updating their code and obfuscating it with VMProtect, an application for protecting software against reverse engineering and code cracking.
Wosar did not rest and released a decrypter for this version as well, which was called ApocalypseVM.
A week after that, the ransomware authors of Apocalypse released a new version, and it contained a kind of «message» for the Emsisoft researchers.
This is not the first time Emsisoft and Fabian Wosar have upset ransomware developers, something similar happened when he created a decrypter for the Radamant ransomware this winter.
“Due to the nature of anti-virus software, it is rather ineffective. If the attacker manages to gain access to the system via remote control, they can simply disable any installed anti-virus software or add the malware to the anti-virus software’s exclusion list,” Emsisoft explains. “Therefore, it is imperative to prevent the attacker from gaining access to the system.”
To this end, it is recommended that sysadmins use strong passwords for their RDP connections, or better yet, simply disable the protocol if they don't need it.

