A new ransomware operation, known as Lorenz, is targeting organizations around the world and demanding hundreds of thousands of dollars.
The Lorenz gang began operating last month and already has a long list of victims, whose data has been published on a data leak site.
See also: Brenntag: Chemical distribution company paid $4.4 million to DarkSide ransomware

Michael Gillespie told BleepingComputer that the Lorenz ransomware encryptor is identical to a previous ransomware operation known as ThunderCrypt. However, it is not known whether the same group is behind the two ransomware or whether the hackers purchased the ThunderCrypt source code to create their own variant (Lorenz).
Data leak site to blackmail victims
Many ransomware gangs tend to compromise a network and spread to other devices until they gain access to Windows domain administrator credentials. This is what the gang behind the Lorenz ransomware does.
As it spreads throughout the system, the gang collects unencrypted files from victims' servers, which it uploads to remote servers controlled by the hackers themselves.
The gang then posts the stolen data on a leakage site data- to pressure victims into paying a ransom. The hackers may also sell the data to other criminals.
See also: XSS: Russian-language hacking forum bans ransomware topics!
The Lorenz ransomware gang's data leak site currently includes twelve victims. The data that has been published belongs to ten of the victim companies.
However, there is a difference compared to other gangs.
To pressure victims into paying the ransom, hackers make the stolen data available for sale to other criminals or potential competitors. Over time, password-protected RAR files containing the victim's data begin to circulate.
If the ransom is not paid and the data is not purchased, the Lorenz gang removes the password and publishes the data for free.
Another unique feature is that Lorenz not only sells data but also access to the victim's internal network. This is very interesting. Cybercriminals may be more interested in access to a network than data.
Lorenz encryption
Lorenz samples that have been examined show that hackers tailor malware depending on the organization they are targeting.
In one of the samples seen by BleepingComputer, the ransomware issues commands to launch a file named ScreenCon.exe from what appears to be the local network's domain controller.
When encrypting files, the ransomware uses AES encryption. The .Lorenz.sz40 extension is added to the encrypted files.
Each folder on the computer displays a ransom note named HELP_SECURITY_EVENT.html, which contains information about what happened to the victim's files. It also includes a link to the Lorenz data leak site and a link to a unique Tor payment site, where the victim can see the ransom amount they have to pay. Victims must pay the ransom in Bitcoin.
See also: FBI and CISA issued alert about DarkSide ransomware

The money demanded by the Lorenz ransomware gang is said to be between $500,000 and $700,000.
However, victims should avoid paying the ransom. Researchers are analyzing the ransomware and a decryption tool may be released soon.
Source: Bleeping Computer
