Crooks are working on a new ransomware brand that destroys your master boot record (MBR), just like Petya did last March. It’s called Satana (“Satan” in some Latin languages), and this ransomware is a combination of a classic ransomware and Petya.
Satana works by encrypting your files, using the same methods that other ransomware families use. For each encrypted file, this new ransomware inserts the crook's email address in front of each file, something like this: “email@domain.com____filename.extension”
Satana then encrypts the MBR and replaces it with its own. The first time a user reboots their computer, Satana's MBR boot code will be loaded and the computer will not boot, displaying its ransom note.
Malwarebytes security researcher hasherezade says that it is possible to recover the original MBR, but that won't necessarily recover the rest of the encrypted files. Recovering MBR files through Windows ' cumbersome command-line interface is something that very few people are able to do properly, so even this process may not be 100% successful in helping users regain access to their computer.
The encryption algorithm used for the remaining files is very strong and cannot be brute-forced, leaving the files locked unless the user decides to pay the ransom, which hasherezade would not advise.
“Even victims who pay may not get their files back if they (or the C&C server) are offline when the encryption occurs,” he writes.
According to the Malwarebytes analyst, the ransomware looks like a work in progress, as its developers are still experimenting with its code, which contains many bugs, so this may not be the last we hear about Satana.
After Petya emerged in March, a month later, security researchers found a way to recover the files that had been locked.
A month later, in May, the crooks changed the way they distributed the Petya package with a second ransomware called Mischa, which was a common ransomware that locked files, while Petya locked the MBR. Satana appears to be an evolution of this latter idea.



