UPDATED 23:22 EDT / JUNE 04 2017

INFRA

In a new twist, Jaff ransomware linked to dark web forum owners

It’s well-known in cybersecurity circles that those behind various forms of malware often sell the data they steal on the dark web, the sometimes shady sites reachable only through specialized software. Now, in an interesting twist, a dark web forum may be behind a recently launched new form of malware, according to newly published research.

The claim comes from Andra Zaharia, a security evangelist at Heimdal Security, who writes that researchers at the company have discovered that Jaff shares server space with a cybercrime dark web store that provides access to tens of thousands of compromised bank accounts.

“Banks from all over the world are listed,” Zaharia said. “Other types of user accounts that include financial data are available as well. Unsuspecting Internet users who have shopped online at Apple, Bed, Bath & Beyond, Barnes & Noble, Best Buy, Booking.com, Asos.com and many other e-commerce portals can become victims of cyber fraud or other types of malicious activity.”

The Jaff ransomware first appeared in early May around the same time WannaCry first appeared, if not with the same mainstream media attention. Jaff is far closer in type to a previous form of ransomware called Locky that ran riot in 2016 and even uses the same payment site template, though there are some differences, including the use of infected PDF files with an embedded “DOCM” file that contains a malicious macro script. Once through the door of a victim’s computer, Jaff encrypts files and demands a ransom of 2 bitcoin, which equals about $5,130.

According to Zaharia, the Russians are actually to blame. The server behind Jaff and the related dark web marketplace was traced to St. Petersburg.

“By combining these informational assets, cybercriminals are engaging in both the long game, required to monetize stolen card data, and in quick wins, such as targeted ransomware attacks, whose simpler business model yields a fast return on investment,” Zaharia added.

Image: sheila_sund/Flickr

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.