A new ransomware operation is hacking Zimbra servers to steal emails and encrypt files. However, instead of demanding a ransom, the attackers claim to be asking for a donation to a charity. After the donation, the hackers will supposedly give the victim a decryption tool and not leak the stolen data

The ransomware operation, dubbed MalasLocker by BleepingComputer, began encrypting Zimbra servers towards the end of March 2023. Several victims reported on both the BleepingComputer and Zimbra forums that emails were encrypted.
Many of the victims reported finding suspicious JSP files uploaded to /opt/zimbra/jetty_base/webapps/zimbra/ or /opt/zimbra/jetty/webapps/zimbra/public folders.
These files were found with different names (e.g., info.jsp, noops.jsp and heartbeat.jsp).
See also: ScanSource announced it had fallen victim to a ransomware attack
When encrypting email messages, no extension is added to the file. However, security researcher MalwareHunterTeam told BleepingComputer that hackers append a message saying “This file is encrypted, look for README.txt for decryption instructions” to the end of each encrypted file.
At present, we do not know how the threat actors are compromising Zimbra servers.
Donation instead of ransom
The ransomware leaves a ransom note named README.txt that states that in order to receive a decryption tool and prevent the leakage of stolen data, must make a donation to a non-profit charity “approved” by the hackers.
“Unlike traditional ransomware groups, we do not ask you to send us money. We simply dislike corporations and economic inequality,” the MalasLocker ransomware ransom note states.
“We simply ask you to make a donation to a non-profit organization we approve. It's win-win, you may get a tax deduction and good PR from your donation, if you wish“.
The ransom notes contain either an email address to contact the hackers or a TOR URL that includes the most recent email for the group. They do not contain a link to the ransomware gang’s data leak website. However, Emsisoft threat analyst Brett Callowfound a link to the website titled, “Somos malas… podemos ser peores” (translation: “We are bad… we can be worse”).
See also: Ransomware group stole data of 5.8 million PharMerica patients
The data leak website currently includes stolen data for three companies and Zimbra configuration for another 169 victims.
The website's main page also contains a long message filled with emojis explaining what the hackers stand for and the ransom they demand.

“We are a new ransomware group that encrypts computers to ask them to donate money to whoever they want,” the MalasLocker ransomware data leak website states.
“We ask that they make a donation to a non-profit organization of their choice and then save the email they receive confirming the donation and send it to us so we can check the DKIM signature to make sure the email is real,” the hackers say.
This requirement is quite unusual. If it is true that after the donation, the hackers give the decryption tool, then their action is placed more in the context of hacktivism.
See also: RA Group ransomware: Targets companies in the US and South Korea
However, we still do not know if the attackers keep their word.
Even if payment has to be made through a donation, the attack does not change. Ransomware is one of the biggest threats in cyberspace today. However, there are some steps you can take to protect yourself. Updating software, using antivirus software, backing up your data, and paying attention to incoming emails are all effective measures you can take. With these precautions, you can significantly reduce the risk of being targeted by ransomware and avoid the financial and emotional toll of a successful attack.
Source: www.bleepingcomputer.com
