
Until now, cybercriminals have used digital currencies to collect ransoms from ransomware . This method, which relies on anonymity, has made this type of attack very profitable for cybercriminals. However, it seems that money is not the only way for victims to pay their ransom to hackers.
Last week, the SonicWALL Capture Labs Research team spotted yet another ransomware. Like any other ransomware, its behavior was no different from the typical one, however this variant demands an Amazon gift card as a form of ransom payment in order to unlock the victim's computer.
Infection process
The way the ransomware works is to transfer the targeted computer's files to the %Temp% directory:
%Temp%/wallpaper.bmp
%Temp%/wallpaper.png
%Temp%/Winrar.exe (non-malicious legal copy of winrar)
It changes the desktop wallpaper of the infected machine using one of the wallpaper image files transferred to the Temp directory.
The ransomware then moves all files in the %Users% directory into encrypted rar file format, using Winrar.exe. It empties the following folders:

Once this is done, a window opens with instructions on how the victim should pay the ransom.
The ransomware creator is asking for the code for a $50 Amazon gift card, in the form of a message, using an app called Discord to the user “UNNAM3D #6666”.
Additionally, a video has been discovered on YouTube, which appears to be from the same creator who is selling malware for $1500.
