Criminals caught trying to recruit insiders to plant ransomware

Employees offered cut of proceeds if they deploy DemonWare on their behalf

Security researchers have discovered a new campaign where cyber criminals offer money to a victim organization’s staff to install ransomware on their behalf.

Researchers at Abnormal Security identified several emails criminals sent to their customers soliciting their help in an insider threat scheme. The aim was for them to infect their companies’ networks with ransomware. Researchers said the emails came from someone with ties to the DemonWare ransomware group.

The latest campaign, criminals told employees they would receive $1 million in Bitcoin — 40% of the presumed $2.5 million ransom — if they deployed ransomware on a company computer or Windows server.

“The employee is told they can launch the ransomware physically or remotely. The sender provided two methods to contact them if the employee is interested—an Outlook email account and a Telegram username,” said researchers.

Crane Hassold, director of threat intelligence with Abnormal Security, said to better understand what was happening, the firm set up a fictitious persona and contacted the hackers on Telegram to see if they could get a response. 

"It didn't take long for a response to come back, and the resulting conversation gave us an incredible inside look at the mindset of this threat actor."

"Based on our conversation with the actor, he claimed to have successfully deployed the ransomware against three companies; however, we haven't been able to verify his claims,” he added.

A half-hour later, the actor responded and asked whether the researcher, posing as a prospective accomplice, could access our fake company’s Windows server. The researcher affirmed this and was then sent two links for an executable file we could download on WeTransfer or Mega.nz, two file sharing sites.

Based on an analysis of the file, researchers confirmed the files were ransomware. Further investigation confirmed the hacker was Nigerian. The hacker also claimed to have developed the DemonWare ransomware, although researchers said all code for DemonWare is freely available on GitHub.

“In this case, our actor simply needed to download the ransomware from GitHub and socially engineer someone to deploy the malware for them,” said Hassold.

Related Resource

How to reduce the risk of phishing and ransomware

Top security concerns and tips for mitigation

Large letter 'O' against a background of a city - whitepaper from MimecastDownload now

Hassold said knowing the hacker is Nigerian brings the entire story full circle and provides some notable context to the tactics used in the initial email identified.

“For decades, West African scammers, primarily located in Nigeria, have perfected the use of social engineering in cyber crime activity,” Hassold said.

“While the most common cyber attack we see from Nigerian actors (and most damaging attack globally) is business email compromise (BEC), it makes sense that a Nigerian actor would fall back on using similar social engineering techniques, even when attempting to successfully deploy a more technically sophisticated attack like ransomware,” Hassold added.

Featured Resources

The definitive guide to warehouse efficiency

Get your free guide to creating efficiencies in the warehouse

Free download

The total economic impact™ of Datto

Cost savings and business benefits of using Datto Integrated Solutions

Download now

Three-step guide to modern customer experience

Support the critical role CX plays in your business

Free download

Ransomware report

The global state of the channel

Download now

Recommended

Researchers disclose top flaws abused by ransomware gangs
ransomware

Researchers disclose top flaws abused by ransomware gangs

20 Sep 2021
One-in-seven Nasdaq-100 companies ranked as highly susceptible to a ransomware attack
cyber crime

One-in-seven Nasdaq-100 companies ranked as highly susceptible to a ransomware attack

16 Sep 2021
Dual citizen sentenced to 11 years for role in North Korean crypto hacking scheme
hacking

Dual citizen sentenced to 11 years for role in North Korean crypto hacking scheme

10 Sep 2021
IoT devices are more vulnerable than ever
Internet of Things (IoT)

IoT devices are more vulnerable than ever

10 Sep 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
Google takes down map showing homes of 111,000 Guntrader customers
data breaches

Google takes down map showing homes of 111,000 Guntrader customers

2 Sep 2021
Intuit plans end-to-end SMB platform after $12 billion Mailchimp acquisition
mergers and acquisitions

Intuit plans end-to-end SMB platform after $12 billion Mailchimp acquisition

14 Sep 2021