Security researchers found a ransomware family that can securely encrypt files, even if the victim does not have an internet connection.
In the past, ransomware blocked access to a computer screen by displaying a full-screen message that was difficult to remove. The first stage of evolution was when ransomware started encrypting the user’s files, but this type of ransomware was not effective because it had to store the encryption key somewhere on the computer. However, Antivirus companies simply scanned the encryption keys and then provided ransomware removal tools.
This has changed in recent years, when ransomware groups began using Internet connections to encrypt the user's file and then send the encryption key to one of their C&C servers. If the user still wanted access to his files, he had to pay the ransom.
Now, researchers at Check Point report a new ransomware family that manages to encrypt files without storing the full decryption key locally, despite the lack of an Internet connection.
The ransomware does this by creating a local RSA public key, which it uses to encrypt the files and then stores in the metadata of each file. When a victim wants their data decrypted, they can contact the ransomware operators via email (adding the name of each file) and send one of the encrypted files as an attachment.
The ransomware operator looks at the file metadata, extracts the RSA public key generated on the user side and matches it with his own RSA private key database.
Check Point staff stated that a brute force attack on the ransomware, as it could take up to 2 years.
As the researchers say, this is one of those cases the FBI talked about when it said that sometimes it's better to pay the ransom.
For this particular ransomware, the ransom is 20,000 Russian rubles ($300). Yes, your intuition is correct: the ransomware was created by Russian hackers.
After further research on this topic, Check Point staff managed to discover the traces of this specific ransomware dating back to June 2014. Antivirus companies have previously detected it under different names:
Win32.VBKryjetor.wfa (Kaspersky)
Ransomcrypt.U (Symantec)
Ninja Ransοmware (Enigma Software)
Troj / Agent-AOTR (Sophos)
Troj / Drop-HQ (Sophos)
Troj / Ransom-ΑΖΤ (Sophos)
Troj / Ransom-BGX (Sophos)
Troj / Ransom-BJQ (Sophos)
Troj / Ransom-BJV (Sophos)
Troj / Agent-ANBL (Sophos)
Troj / Ruftar-H (Sophos)
Troj / VB-IHK (Sophos)
Mal / Delp-AI (Sophos)

