A strange ransomware is taking an unusual approach as it sells its decryptor on the Roblox gaming platform , using the service's Robux currency .
See also: Roblox: The most popular game that has driven kids crazy

Roblox is an online gaming where members can create their own games and monetize them by selling Game Passes, which provide in-game items, special access, or enhanced features.
To pay for these game cards, members use an in-game currency, called Robux.
Security researcher MalwareHunterTeamhas discovered a new ransomware called “WannaFriendMe” that impersonates the infamous Ryuk Ransomware. However, it is actually a variant of the Chaos Ransomware.
In June 2021, a malicious actor began selling a Chaos ransomware creation program, which allowed criminals to create their own ransomware infection with customized ransom notes, encrypted file extensions, and other features.
See also: Cuba ransomware: New version detected in recent attacks
By default, the Chaos creator pretends to be Ryuk, using the .ryuk on encrypted files.

What makes the new WannaFriendMe ransomware stand out is that instead of demanding cryptocurrency as a ransom payment, it requires victims to purchase a decryptor from Roblox's Game Pass store using Robux, as the ransom note states.
When the victim visits the URL in the Roblox Game Pass store, they can see that the "Ryuk Decrypter", sold by a user named "iRazormind" for 1,499 Robux and last updated on June 5th.
The problem with Chaos ransomware variants is that they not only encrypt your data but also destroy it in many cases.
See also: Black Basta ransomware: Linux version targets VMware ESXi servers
When encrypting a device, any file larger than 2 MB will be replaced with random data and will not be encrypted. This means that even if you purchase a decryptor, only files smaller than 2 MB can be recovered.
While it is unclear how this ransomware is distributed or whether it has been used in attacks, its destructive nature and targeting of young gamers could lead to significant damage.
