A ransomware targeting an Israeli company has led researchers to trace part of a ransom payment to a website promoting sensual massages, the .

See also: Hackers combine ransomware and DDoS attacks to target victims
The attack was carried out by a more recent ransomware operation, known as Ever101, which breached an Israeli “computer farm” and proceeded to encrypt its devices.
In a new report by Israeli cybersecurity firms Profero and Security Joes, it is stated that Ever101 is believed to be a variant of the Everbe or Paymen45 ransomware.
When encrypting files, the ransomware will append the .ever101 extension and display a ransom note with !=READMY=!.txt in every folder on the computer.

See also: Researchers analyze the LockBit ransomware "operation"
While investigating one of the infected machines, researchers found a “Music” folder containing various tools used during the attack, providing insight into the threat actor’s tactics, techniques, and procedures. Interestingly, some of the files shared by the attackers, such as WinRar, were found to be in Arabic.

Of particular interest is what researchers discovered after using CipherTrace to track the ransom payment as it flows through different bitcoin wallets.
Tracing the payment, they found that a small portion of the ransom (0.01378880 BTC, or about $590), was sent to a “Tip Jar” on the RubRatings website.
RubRatings is a website that allows “massage providers” in the US to advertise their services, many of them offering sensual massage.
Each masseuse profile includes a Tip Jar button that allows customers to leave a bitcoin tip for their recent massage.

See also: Ransomware: Many companies will pay the ransom if attacked
Researchers believe that part of the ransom payments went to an Ever101 agent in the US, who then used the coins to tip a masseuse, or more likely, use the website as a way to launder the ransom payment.
As bitcoin is easily detected by law enforcement, ransomware operations are looking for new approaches to launder their ill-gotten gains.
So it is possible that the threat actors created a fake account on RubRatings and used the Tip Jar feature as a way to launder the ransom.
Information source: bleepingcomputer.com
