HomeSecurityORX-Locker, the new Darknet Ransomware-as-a-service platform

ORX-Locker, the new Darknet Ransomware-as-a-service platform

Security experts at Sensecy have discovered ORX-Locker, a Darknet Ransomware-as-a-service platform that could allow anyone to become a cybercriminal.

It's becoming even easier to become a cybercriminal thanks to a sales model known as malware-as-a-service, which offers off-the-shelf malware for rent or sale. Recently, malware writers have also started offering Ransomware-as-a-Service (RaaS), and in August, McAfee security experts discovered a ransomware-based kit on the Deep Web, dubbed the Tox ransomware platform, which allows for easy building of malware in just 3 steps, providing this model for sale.

Now experts at Sensecy are warning about a new RaaS platform called ORX-Locker. ORX-Locker allows criminals to create their own piece of malware to infect systems and demand payment of some kind of fee to unlock the system.

In the RaaS model, when victims decide to pay, the malware redirects them through a service provider, which keeps a percentage of the fee and forwards the rest to the criminal.

ORX-Locker employs a sophisticated AV evasion method and complex communication techniques. Researchers discovered that it uses universities and other platforms as control infrastructures.

The first appearance of ORX ransomware is dated August 25, 2015, when a user named orxteam announced the availability of a new RAAS service in a post.

ORX-Locker

The ORX team developed a hidden service for the RaaS implementation, experts emphasize that the site requires some details for new users.

“To enter the site, new users simply need to register. No email or other identifying information is required. Upon registration, users have the option to enter a relevant username, which will reward them with three percent of every payment made by a new user,” emphasizes the publication that provides a detailed description of the ORX platform.

To create a ransomware fragment, users simply need to add the ID number (5 digits maximum) and the ransom price (ORX has set a minimum of $75), and then they need to click the Build EXE button.

The user can easily withdraw their winnings by transferring them to a Bitcoin address using the Wallet feature. The ORX-Locker platform additionally implements a user-friendly interface with statistics for its users.
The ORX Ransomware is a zip file containing the binary for the malware.

Researchers at Sensecy have identified the addresses belonging to the C&C infrastructure:

  1. 130[.]75[.]81[.]251 – Leibniz University of Hanover
  2. 130[.]149[.]200[.]12 – Technical University of Berlin
  3. 171[.]25[.]193[.]9 – DFRI (Swedish non-profit and non-partisan organization working for digital rights)
  4. 199[.]254[.]238[.]52 – Riseup (Riseup provides online communication tools for individuals and groups working for liberatory social change)

ORX ransomware encrypts the victim's files and informs them about the infection by displaying a pop-up message, it also creates a file on the desktop containing the payment order.

ORX-Locker

The publication made by Sensecy researchers includes the Yara rule for malware detection.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS