Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Ransomware Toolkit Cryptonite turning into an accidental wiperSecurity Affairs

Altszn.com by Altszn.com
December 6, 2022
in Dark Web
0
Ransomware Toolkit Cryptonite turning into an accidental wiperSecurity Affairs
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


Researchers spotted a version of the open-source ransomware toolkit Cryptonite that doesn’t support decryption capabilities.

Fortinet researchers discovered a sample of malware generated with the publicly available open-source ransomware toolkit Cryptonite that never offers the decryption window, turning it as a wiper. The experts also reported an increase in ransomware intentionally turned into wiper malware, these malicious code are mainly employed in politically-motivated campaigns.

The ransomware toolkit was published on GitHub by a threat actor that goes under the name CYBERDEVILZ. Fortinet noticed that after one of its Ransomware Roundup series the source code and its forks have since been taken down.

The researchers believe that the toolkit isn’t a serious tool, it only implements a limited set of ransomware functionalities.

The encryption and decryption are not robust and the ransomware lack features like Windows Shadow Copy removal, File unlocking for a more thorough impact, Anti-analysis, and Defensive evasion (AMSI bypass, disabling event logging, etc.).

The sample analyzed by the expert masquerades as a software update, it shows a progress bar that represents the progress of encryption.

cryptonite ransomware toolkit

The sample is written in python and is bundled with pyinstaller into an executable, static analysis of the code revealed that the authors removed a portion of code used to enumerate the filesystem breaking the program’s functionality.

The dynamic analysis of the code shows program crashes when the ransomware tries to use the tkinter library in the warningScreen()function.

“The traceback shows that the ransomware fails when it tries to use the tkinter library in the warningScreen()function. At this point in this ransomware, the encryption process has already finished. The warningScreen() should show the ransom note and allow the victim to start the decryption.” reads the analysis published by Fortinet. “We can now see that the ransomware was not intentionally turned into a wiper. Instead, the lack of quality assurance led to a sample that did not work correctly. The problem with this flaw is that due to the design simplicity of the ransomware if the program crashes—or is even closed—there is no way to recover the encrypted files.”

The malware uses the Fernet module of the cryptography package to encrypt files.

“This sample demonstrates how a ransomware’s weak architecture and programming can quickly turn it into a wiper that does not allow data recovery. Although we often complain about the increasing sophistication of ransomware samples, we can also see that oversimplicity and a lack of quality assurance can also lead to significant problems.” concludes the report. “On the positive side, however, this simplicity, combined with a lack of self-protection features, allows every anti-virus program to easily spot this malware.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, cryptonite ransomware toolkit)










Share On








Read More: news.google.com

Tags: accidentalaffairsCryptonitedark webDarknetransomwaretoolkitturningwiperSecurity
ADVERTISEMENT

Recent

TON Foundation Hires Former Visa Exec to Lead Global Payments

TON Foundation Hires Former Visa Exec to Lead Global Payments

May 28, 2025
AMINA Bank Posts Record $40.4M Revenue in 2024

AMINA Bank Posts Record $40.4M Revenue in 2024

May 28, 2025
Metaplanet issues $50M in zero-interest bonds to boost Bitcoin holdings

Metaplanet issues $50M in zero-interest bonds to boost Bitcoin holdings

May 28, 2025

Categories

  • Bitcoin (4,602)
  • Blockchain (10,944)
  • Crypto (8,887)
  • Dark Web (469)
  • DeFi (8,180)
  • Ethereum (4,635)
  • Metaverse (6,977)
  • Monero (258)
  • NFT (1,185)
  • Solana (4,952)
  • Web3 (20,049)
  • Zcash (473)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    TON Foundation Hires Former Visa Exec to Lead Global Payments

    TON Foundation Hires Former Visa Exec to Lead Global Payments

    May 28, 2025
    AMINA Bank Posts Record $40.4M Revenue in 2024

    AMINA Bank Posts Record $40.4M Revenue in 2024

    May 28, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 108,356.00
    • ethereumEthereum (ETH) $ 2,666.06
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.29
    • bnbBNB (BNB) $ 685.15
    • solanaSolana (SOL) $ 173.56
    • usd-coinUSDC (USDC) $ 0.999799
    • dogecoinDogecoin (DOGE) $ 0.222282
    • cardanoCardano (ADA) $ 0.754002
    • tronTRON (TRX) $ 0.274974
    • staked-etherLido Staked Ether (STETH) $ 2,659.86
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 108,361.00
    • suiSui (SUI) $ 3.68
    • hyperliquidHyperliquid (HYPE) $ 34.56
    • wrapped-stethWrapped stETH (WSTETH) $ 3,200.92
    • chainlinkChainlink (LINK) $ 15.87
    • avalanche-2Avalanche (AVAX) $ 23.38
    • stellarStellar (XLM) $ 0.286917
    • the-open-networkToncoin (TON) $ 3.42
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 9.06
    • bitcoin-cashBitcoin Cash (BCH) $ 414.74
    • hedera-hashgraphHedera (HBAR) $ 0.185999
    • wethWETH (WETH) $ 2,660.94
    • litecoinLitecoin (LTC) $ 96.25
    • usdsUSDS (USDS) $ 0.999882
    • polkadotPolkadot (DOT) $ 4.57
    • wrapped-eethWrapped eETH (WEETH) $ 2,846.12
    • moneroMonero (XMR) $ 353.36
    • bitget-tokenBitget Token (BGB) $ 5.33
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • pepePepe (PEPE) $ 0.000014
    • pi-networkPi Network (PI) $ 0.738571
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 108,247.00
    • whitebitWhiteBIT Coin (WBT) $ 31.73
    • aaveAave (AAVE) $ 268.79
    • uniswapUniswap (UNI) $ 6.78
    • bittensorBittensor (TAO) $ 441.50
    • daiDai (DAI) $ 1.00
    • nearNEAR Protocol (NEAR) $ 2.85
    • aptosAptos (APT) $ 5.35
    • jito-staked-solJito Staked SOL (JITOSOL) $ 208.29
    • okbOKB (OKB) $ 52.16
    • tokenize-xchangeTokenize Xchange (TKX) $ 38.94
    • ondo-financeOndo (ONDO) $ 0.945547
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.097822
    • internet-computerInternet Computer (ICP) $ 5.34
    • ethereum-classicEthereum Classic (ETC) $ 18.64
    • bitcoinBitcoin (BTC) $ 108,356.00
    • ethereumEthereum (ETH) $ 2,666.06
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.29
    • bnbBNB (BNB) $ 685.15
    • solanaSolana (SOL) $ 173.56
    • usd-coinUSDC (USDC) $ 0.999799
    • dogecoinDogecoin (DOGE) $ 0.222282
    • cardanoCardano (ADA) $ 0.754002
    • tronTRON (TRX) $ 0.274974
    • staked-etherLido Staked Ether (STETH) $ 2,659.86
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 108,361.00
    • suiSui (SUI) $ 3.68
    • hyperliquidHyperliquid (HYPE) $ 34.56
    • wrapped-stethWrapped stETH (WSTETH) $ 3,200.92
    • chainlinkChainlink (LINK) $ 15.87
    • avalanche-2Avalanche (AVAX) $ 23.38
    • stellarStellar (XLM) $ 0.286917
    • the-open-networkToncoin (TON) $ 3.42
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 9.06
    • bitcoin-cashBitcoin Cash (BCH) $ 414.74
    • hedera-hashgraphHedera (HBAR) $ 0.185999
    • wethWETH (WETH) $ 2,660.94
    • litecoinLitecoin (LTC) $ 96.25
    • usdsUSDS (USDS) $ 0.999882
    • polkadotPolkadot (DOT) $ 4.57
    • wrapped-eethWrapped eETH (WEETH) $ 2,846.12
    • moneroMonero (XMR) $ 353.36
    • bitget-tokenBitget Token (BGB) $ 5.33
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • pepePepe (PEPE) $ 0.000014
    • pi-networkPi Network (PI) $ 0.738571
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 108,247.00
    • whitebitWhiteBIT Coin (WBT) $ 31.73
    • aaveAave (AAVE) $ 268.79
    • uniswapUniswap (UNI) $ 6.78
    • bittensorBittensor (TAO) $ 441.50
    • daiDai (DAI) $ 1.00
    • nearNEAR Protocol (NEAR) $ 2.85
    • aptosAptos (APT) $ 5.35
    • jito-staked-solJito Staked SOL (JITOSOL) $ 208.29
    • okbOKB (OKB) $ 52.16
    • tokenize-xchangeTokenize Xchange (TKX) $ 38.94
    • ondo-financeOndo (ONDO) $ 0.945547
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.097822
    • internet-computerInternet Computer (ICP) $ 5.34
    • ethereum-classicEthereum Classic (ETC) $ 18.64