HomeinetNew improved DMA Locker in version 4.0, preparing for attacks

New improved DMA Locker in version 4.0, preparing for attacks

Malwarebytes security researcher Hasherezade discovered that the recent version of the DMA Locker ransomware has significantly improved its malicious processes, and is preparing for a mass distribution campaign.DMA Locker ransomware

The first version of DMA Locker appeared last January. Technically, the ransomware was a joke, as it contained hilarious flaws, such as the decryption key being embedded in the ransomware code. This fact made the malware itself a Decrypter.

So the researchers had no problem since they had the Decrypter in their hands which helped to recover infected files. The same was true with DM Locker in version 2.0, which appeared almost a month later, in early February. Nevertheless, the crooks managed to develop version 3 and 4 which are currently considered undecryptable, or to put it differently, impossible to decrypt.

Version 3.0, released in late February, was the first that analysts could not crack, as it used a better encryption system.

As for version 4.0 of DM Locker, the new application features many improvements, which now place the malware from the moderate ransomware risk category near the top.

The ransomware, which always operated offline, now uses a command and control (C&C) server. Instead of a single encryption key that was embedded in the ransomware itself, the new DMA Locker generates unique AES encryption keys for each file which it encrypts with a public RSA key obtained from the C&C server.

So to decrypt all the locked files, the user needs the other part of the RSA key, which is called the RSA private key. This key does not exist and will never exist on the user's computer. To obtain the key, the victim will have to contact the developers of DMA Locker.

Older versions of the ransomware required users to send an email to the developer to obtain the decryption keys. DMA Locker 4.0 is fully automated and comes with its own website where users can pay their ransom, just like other ransomware.

However, the website is not fully functional, and Hasherezade reports that the decryption test did not return the decrypted file. Furthermore, the website is hosted on a public IP, not the Dark Web, making it susceptible to takedowns and detection.

The website is even hosted by the same IP address used by the C&C server, which is not so smart on the part of the scammer.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS