HomeSecurityINC Ransom: Is the ransomware source code being sold?

INC Ransom: Is the ransomware source code being sold?

A cybercriminal with the nickname “salfetka” claims to be selling the source code of the INC Ransom ransomware.

INC Ransom ransomware source code

The ransomware appeared in August 2023 and has targeted Xerox Business Solutions (the US division), Yamaha Motor Philippines , and, most recently, the Scottish National Health Service (NHS).

It is worth noting that at the same time as the alleged sale, the operation is undergoing changes that may indicate a rift between key members of its team. However, it may simply be changes to use a new encryptor.

See also: INC Ransom behind Leicester City Council attack

INC Ransom ransomware: Source code for sale

salfetka announced the sale of both the versions Windows and Linux/ESXi hacking forums, asking for $300,000. He also said that only three people can purchase the ransomware's source code.

KELA experts , who spotted the sale, reported that indeed the technical details mentioned in the post (e.g. use of AES-128 in CTR mode and Curve25519 Donna algorithms) align with the INC Ransom ransomware samples that have been analyzed. Furthermore, both the old and new URLs INC Ransom page are included in the signature, indicating a connection to the ransomware operation

KELA also told BleepingComputer that “salfetka” had been active on hacking forums since March 2024.

However, the sale could be a scam, with the attacker carefully curating the “salfetka” account over the past few months

Currently, there are no public announcements on the old or new INC Ransom website regarding the sale of the ransomware source code.

See also: National Health Service Scotland: INC Ransom hackers threaten data leak

INC Ransom: Is the ransomware source code being sold?

INC Ransom: New website

On May 1, 2024, the INC Ransom group announced on the old data that it would be moving to a new extortion “blog” and shared a new TOR address, stating that the old website would be shut down in two to three months.

The new website is already up and running, and there are some old victims (victims who were also on the old site) as well as a dozen new victims. In total, the new website lists 64 victims. The old one had 91, meaning that many of the old victims are not listed on the new site.

“The discrepancies between the two sites may indicate a change of leadership or a split into different groups,” KELA analysts commented.

“However, the fact that “salfetka” has mentioned both sites suggests that he is probably not only associated with one part of the business… In this case, it is possible that the new blog was created in an attempt to gain more profit from the sale“.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It is also worth noting that the new design of INC Ransom's extortion page visually resembles that of Hunters International, which could suggest a connection between the two.

See also: Ascension: Systems are restored after ransomware

INC Ransom: Is the ransomware source code being sold?

What does a possible sale of the INC Ransom ransomware source code mean?

By selling the code of a ransomware, we may find ourselves faced with new, more dangerous attacks. INC Ransom ransomware is a sophisticated tool and its buyer can improve it further to cause more damage to victims.

Salfetka said that it could be sold to three people, so there would be widespread exploitation of the source code, which could lead to the creation of many new variants and therefore a drastic increase in ransomware attacks.

There is a risk that we will see new versions of INC Ransom ransomware, even more sophisticated and difficult to deal with. At this stage, it is vital that individuals and companies take all preventive measures to protect themselves. This may include promoting cybersecurity, updating software and security systems, and creating backups.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS