HomeSecurityYatron Ransomware Attempts to Spread Through EternalBlue NSA Vulnerabilities

Yatron Ransomware Attempts to Spread Through EternalBlue NSA Vulnerabilities

Yatron

A new Ransomware-as-a-Service called Yatron is being promoted on Twitter, and it plans to use EternalBlue and DoublePulsar to spread to other computers on a network. This ransomware will also attempt to delete encrypted files if payment is not made in 72 hours.

BleepingComputer was first informed about Yatron RaaS by a security researcher, going by the name A Shadow. Since then, the hacker behind this ransomware has been curiously promoting the service via tweets to various security researchers as seen below.

Yatron Ransomware Attempts to Spread Through EternalBlue NSA Vulnerabilities

After seeing one of these tweets, BleepingComputer was able to find a sample on VirusTotal and with the help of Michael Gillespie began examining the ransomware's source code.

Like any other ransomware, when it runs, it will scan the computer for targeted files and encrypt them. When it encrypts a file, it will add the .Yatron extension to an encrypted file name as shown below.

Yatron Ransomware Attempts to Spread Through EternalBlue NSA Vulnerabilities

After the encryption of the files is completed, it will send the encryption key and the unique ID back to the ransomware's command and control server. According to Gillespie, this ransomware is based on HiddenTear, but its encryption algorithm has been modified so that it cannot be decrypted with current methods.

Once the encryption is done, things start to become more interesting.

Yatron contains code to exploit EternalBlue and DoublePulsar, so that it can spread to Windows machines on the same network, using vulnerable SMBv1 that should have been patched long ago. Fortunately, the code for leveraging these exploits is incomplete and the ransomware does not currently include the executable files Eternalblue-2.2.0.exe and Doublepulsar-1.3.1.exe, on which it relies.

In addition to exploiting vulnerabilities, Yatron will attempt to spread via P2P programs, copying the ransomware executable into preselected folders used by programs such as Kazaa, Ares, eMule and many others. The goal is that when these programs start, the ransomware will automatically be shared by the P2P client.

When it is completed, the ransomware will display an interface that contains a 72-hour countdown until the encrypted files are deleted. To protect the files from being deleted, the user can simply terminate the process, using a tool such as Process Explorer as Administrator.

Offered as RaaS

Yatron is marketed as a Ransomware-as-a-Service, but it does things a little differently from most RaaS services.

Usually, when wannabe criminals join an RaaS, its creator receives a revenue share from all paid ransoms. For example, some RaaS services will take 20% of all ransoms, while the partner/distributor earns the remaining 80%.

Like another recent RaaS called Jokeroo, the Yatron developer sells access to the RaaS for $100 in bitcoins and then there is no charge.

Like all RaaS offerings, Yatron promises a FUD executable file, the ability to encrypt a computer and delete backups. As described earlier, this ransomware also aims to spread via P2P, USB and LAN.

However, so far, no one has paid to gain access to this ransomware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS