Introducing the first Ransomware of the Year #2016: Ransom32.
A new Ransomware-as-a-service, called Ransom32, has made its appearance just before the new year and is coming to shake up our… data! It is the first time that a ransomware written in JavaScript affects Mac, Windows and Linux machines!

Ransom32 allows operators to deploy malware very quickly and easily. It has a dashboard that allows administrators to specify which Bitcoin addresses the ransom will be sent to. This dashboard also displays statistics on how many Bitcoins they have earned.
In short, the new ransomware-as-a-service is so simple, and so effective at the same time, that anyone can download and share their own copy of the ransomware executable as long as they have a Bitcoin address.
The Ransom32 copy was first analyzed by Emsisoft, which discovered that the new ransomware family, which is embedded in a self-extracting WinRAR archive, uses the NW.js platform to infiltrate victims' computers, and then encrypts their files with 128-bit AES encryption.
How does Ransom32 work?
Malware operators place the malicious file inside emails that appear as delivery notifications, unpaid invoices, and the like.
Once installed and launched, Ransom32 connects to a command-and-control (C&C) server on the TOR anonymising network, displaying a ransom note like the one shown in the image and a Bitcoin address where victims must pay the stated amount to get their files back.
So far, we have only seen Ransom32 attack Windows, but the NW.js framework can run on all three major operating systems.
Furthermore, the ransomware was created to be able – theoretically – to affect Mac OS X, as well as Linux operating systems.

How can we protect ourselves from this threat?
We present to you some important steps that we should all take seriously, if we want to protect ourselves from such Ransomware threats:
– Keep regular backups of your most important files (if you can't, the entire volume).
– Make sure you have an active anti-virus security suite of tools on your system.
– Do not open attachments from unknown senders.
– Most importantly of all: Always search and stay informed about your security and all new updates!
