Data extortion market Industrial Spy appears to have started its own ransomware operation, now encrypting victim devices as well.
A new data extortion marketplace called Industrial Spy allows threat actors, and possibly even business competitors, to buy data that has been stolen from companies.
This marketplace sells different types of stolen data, ranging from selling “premium” data for millions of dollars to individual files for as little as $2.
See also: Google says Russian hackers leaked Brexit emails

To promote their service, the threat actors collaborated with adware loaders and “fake crack sites” to distribute malware that would create README.txt files on a device.
The threat actors used these files to promote their marketplace, explaining that readers could purchase schemes, drawings, technologies, political and military secrets, accounting reports, and databases of their competitors.
Industrial Spy enters the ransomware game
Last week, security researcher MalwareHunterTeam found a new sample of the Industrial Spy malware with what looked more like a ransom note than an advertising text file.
This ransom note now states that the Industrial Spy threat actors not only stole the victim's data but also encrypted it.
See also: ChromeLoader: The new malware that modifies browser settings
“Unfortunately, we have to inform you that your company has been hacked. All your files were encrypted and you cannot restore without our private key. Attempting to restore without our help may result in complete loss of your data ,” reads the Industrial Spy ransom note shared below.
“We have also searched your entire corporate network and downloaded all sensitive data to servers . If we do not hear from you within the next 3 days, we will publish your data on the “Industrial Spy Market” website.”

MalwareHunterTeam shared the malware sample with BleepingComputer to confirm whether it encrypted files as it said.
BleepingComputer's tests showed that Industrial Spy ransomware does indeed encrypt files, but unlike most ransomware families, it does not add a new extension to the names of encrypted files, as shown below.

When encrypting files, Industrial Spy ransomware will create the above ransom note named “README.html” in every folder on the device.
These ransom notes contain a TOX identifier that victims can use to contact the ransomware gang and negotiate a ransom payment.
Is it related to Cuba ransomware?
While investigating the TOX ID and email address found in the ransom note, MalwareHunterTeam discovered a strange connection to the Cuba ransomware.
A ransomware sample uploaded to VirusTotal creates a ransom note with an identical TOX ID and email. However, instead of linking to the Industrial Spy Tor website, it links to the Cuba Ransomware data leak website and uses the same filename, !! READ ME !!.txt, as Cuba.

Additionally, the encrypted files have the .cuba extension appended, just like the regular Cuba ransomware does when encrypting files.
While this doesn't 100% connect the two groups, it's very possible that the Industrial Spy threat actors simply used Cuba's information while testing their ransomware creation.
See also: Linux ransomware 'Cheers': Targets VMware ESXi servers
However, it's a bit strange and is definitely something that security researchers and analysts should keep an eye on.
Information source: bleepingcomputer.com
