If you ever get hit by ransomware that encodes the names of encrypted files using the .stn extension, then you are a victim of Satan, not the “Prince of Darkness,” but of the eponymous new Ransomware service. Yes, a new Ransomware as a Service is circulating online.
The new ransomware was discovered on Wednesday by security researcher Xylitol and as it turns out, the new RAAS is being marketed via underground forums.
Anyone can use Satan for free, the vendor states, but they will have to pay 30 percent of each successful ransom payment in exchange for providing the service.
A visit to the service's website (on Tor) reveals a very well-designed page that offers users the ability to create a variant of the malware to their liking.
Those interested can choose techniques to hide the dropper, and have the ability to translate the ransom note, change ways of communicating with the victim, or choose how the malware communicates with them.
Through this website, registered users using the service can also see how many of their ransomware attacks have been successful, and the amount they have earned so far.
At this time, we do not know the encryption method used by Satan, so it is probably too early to talk about a decryption tool.
So be careful in your online travels because unfortunately Satan RAAS is extremely easy to use and accessible to anyone who has no qualms, even if they do not have any special knowledge.
