HomeSecurityMysterious ransomware payment detected on RubRatings site

Mysterious ransomware payment detected on RubRatings site

A ransomware targeting an Israeli company has led researchers to trace part of a ransom payment to a website promoting sensual massages, the .

RubRatings ransomware

See also: Hackers combine ransomware and DDoS attacks to target victims

The attack was carried out by a more recent ransomware operation, known as Ever101, which breached an Israeli “computer farm” and proceeded to encrypt its devices.

In a new report by Israeli cybersecurity firms Profero and Security Joes, it is stated that Ever101 is believed to be a variant of the Everbe or Paymen45 ransomware.

When encrypting files, the ransomware will append the .ever101 extension and display a ransom note with !=READMY=!.txt in every folder on the computer.

RubRatings

See also: Researchers analyze the LockBit ransomware "operation"

While investigating one of the infected machines, researchers found a “Music” folder containing various tools used during the attack, providing insight into the threat actor’s tactics, techniques, and procedures. Interestingly, some of the files shared by the attackers, such as WinRar, were found to be in Arabic.

RubRatings

Of particular interest is what researchers discovered after using CipherTrace to track the ransom payment as it flows through different bitcoin wallets.

Tracing the payment, they found that a small portion of the ransom (0.01378880 BTC, or about $590), was sent to a “Tip Jar” on the RubRatings website.

RubRatings is a website that allows “massage providers” in the US to advertise their services, many of them offering sensual massage.

Each masseuse profile includes a Tip Jar button that allows customers to leave a bitcoin tip for their recent massage.

RubRatings

See also: Ransomware: Many companies will pay the ransom if attacked

Researchers believe that part of the ransom payments went to an Ever101 agent in the US, who then used the coins to tip a masseuse, or more likely, use the website as a way to launder the ransom payment.

As bitcoin is easily detected by law enforcement, ransomware operations are looking for new approaches to launder their ill-gotten gains.

So it is possible that the threat actors created a fake account on RubRatings and used the Tip Jar feature as a way to launder the ransom.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS