
Evil Corp, one of the largest malware companies, has made headlines again with the distribution of the new WastedLocker ransomware. In December 2019, the US Department of Justice (DOJ) issued indictments against several of the group's members.
Today, a report was released detailing the hacking group's latest activities following the DOJ charges.
A brief history of Evil Corp
The Evil Corp group, also known as the Dridex gang, has been active since 2007. Previously, some of the group members were involved with the banking trojan ZeuS but decided to try their luck at distributing their own malware.
Initially, they focused on distributing the Cridex banking trojan, a malware that evolved into the Dridex banking trojan and later the Dridex multi-purpose malware toolkit.
Over the years, Evil Corp has become one of the largest malware and spam botnets through its Dridex operation. The group distributes its own malware, as well as malware from other criminal groups.
Also, the hacking group started distributing Locky ransomware to home users during 2016. Later, the Evil Corp gang created a new ransomware called BitPaymer.
The group used its massive botnet of computers to search corporate networks and deploy BitPaymer. This happened between 2017 and 2019. In 2019, BitPaymer attacks began to decline, while at the same time, the Dridex botnet began to slow down its activity

Charges from the DOJ
The slowdown in their activities culminated with the DOJ charges filed in December 2019. After the charges, the group went silent for a full month, until January 2020. In January, it started some campaigns again, usually for other scammers.
New attacks were detected in May. The group's new look was accompanied by new tools. The hackers created a completely new ransomware that replaces the old BitPaymer.
New WastedLocker ransomware
Researchers have named the new ransomware WastedLocker, based on the file extension added to encrypted files. The extension usually includes the victim's name and the word "wasted.".
According to expert analysis, there are no commonalities in the code of BitPaymer and WastedLocker. However, some similarities were found in the ransom note text that the ransomware leaves behind.
WastedLocker ransomware has exclusively targeted US companies.
The ransom demanded by Evil Corp runs into the millions. “We’ve seen them ask for over $10 million,” the researchers said.
"Hackers typically target file servers, databases, virtual machines, and cloud environments," the researchers.
Additionally, Evil Corp is trying to cause problems with backups and related infrastructure to make it difficult for victims to recover.
There is no evidence of data theft and site leakage
Apparently, the new WastedLocker ransomware -stealing functionality data.
Lately, about 10-15 ransomware gangs have been infecting corporate networks, stealing data, and then threatening to publish the files online ( leak site).
Evil Corp isn't doing that (for now, at least). Experts say leaking stolen data usually draws media attention, which the hackers likely want to avoid, as some of the members are already on the FBI 's "Cyber Most Wanted" list .
