A threat actor is promoting a new version of the free-to-use ransomware builder “Redeemer” on hacker forums, offering unskilled threat actors an easy entry into the world of encryption-backed extortion attacks.

See also: Atlassian fixes critical flaw in Confluence
According to its author, the new version 2.0 was written entirely in C++ and runs on Windows Vista, 7, 8, 10 and 11, with multi-threaded performance and a medium AV detection rate.
Unlike many Ransomware-as-a-Service (RaaS) operations, anyone can download and use the Redeemer ransomware builder to launch their own attacks. However, when a victim decides to pay the ransom, the author receives 20% of the ransom and shares the master key that will be combined with the affiliate’s private builder key for decryption.
The new version also features a new graphical user interface for the affiliate to create the ransomware executable and decryption tool, while all instructions on how to use it are included in the ZIP.
The author says the project will become open source if they lose interest, just like what happened with Redeemer 1.0 in June 2021, when the threat actor publicly released its source code .
See also: GPS vehicle tracker gives hackers admin rights

Details Redeemer 2.0
The new version of the ransomware creator features many additions, including support for Windows 11, GUI tools, and more communication options, such as XMPP and Tox Chat.
Additionally, there is now a campaign ID tracking system, which adds the data to the executable, allowing threat actors to track various campaigns they may be running.
Because the ransom amount is defined when the executable is created and corresponds to a specific identifier, the affiliate cannot submit arbitrary claims to the creator, so the latter's 20% cut is guaranteed.

The author has created a page on the dark web site Dread for affiliates to obtain the kit, establish contact, access instructions, and receive support.

Cyble researchers, who analyzed the new version, report that the ransomware creates a mutex at startup to avoid multiple instances on the victim's system and abuses Windows APIs to run with administrator privileges.
Before encryption, the malware abuses Windows commands to clear event logs and delete shadow copies and any backups , preventing easy/free restore.
See also: Homeland Security tracks citizens via phone location
Then, the processes shown below are terminated to prevent the encryption process from being compromised.

After that, the ransomware drops a custom icon for Windows to use for expanding encrypted files, creates ransom notes, and lists all files and directories.

Bleeping Computer independently examined the ransomware and found that it did not delete all files after encrypting them, so operation seems unreliable.

When attempting to open one of the encrypted copies, the victim receives a message instructing them to open the ransom note for instructions on what to do.

The ransomware also adds a ransom note to the Winlogon registry key to warn the user about what happened during system restart.

Should you be worried?
While low-level hackers typically lack the skills to initially find access points to valuable corporate networks, they can cause significant damage to many vital but poorly protected entities, such as healthcare and small businesses.
However, the adoption of this new ransomware does not seem very high, but even if the project fails, the promise of releasing the source code creates the bleak prospect of new projects based on the Redeemer source code
Information source: bleepingcomputer.com
