July 7, 2016 By Douglas Bonderud 2 min read

Ransomware just won’t quit. It seems like every month there’s a new strain or variant making the rounds — and making life more difficult for users. The most recent king of the compromise hill was Locky, which not only encrypted files, but scrambled bitcoin wallets and removed Windows shadow copies before demanding payment.

According to Naked Security, however, a new challenger has emerged: Zepto, which shares many of Locky’s worst features. But is this “new Locky” just a stop on the ransomware road or a harbinger of more sinister software?

Familiar Feeling

According to Threatpost, Locky’s successor sent out almost 140,000 spam messages in the last week. While this is on the low end for most ransomware campaigns, it’s impressive given that it’s Zepto’s first appearance, according to Craig Williams of Cisco Talos.

The new malware infects devices using an attached .zip or .docm file. The .zip file contains a JavaScript file that looks like a text document at first glance but runs a ransomware downloader when opened. The .docm files, meanwhile, are “documents with macros.”

What’s interesting here is that macros are disabled by default in Word — when users open the document, they’re greeted with a blank document and a security warning that provides the option to enable macros. In effect, cybercrooks are hoping that natural curiosity will encourage users to do the dirty work of infecting their own machines.

Once installed, Zepto encrypts all files and then directs users to the Locky decryptor pay page, indicating that it’s at least borrowing from its predecessor — but the jury’s still out on whether the ransomware is a Locky variant or copycat. While its email infection numbers aren’t stellar, Williams warned Threatpost that a move to malvertising “could get bad very fast.”

New Tricks for Zepto

Popular Locky features and well-crafted spam emails make Zepto an immediate threat, but the ransomware is more worrisome as a touchstone for the new focus of encryption malware: fear. This is not simply the broad fear of a computer compromise and file loss, but the specific terror of knowing exactly what could disappear.

For Zepto, that means tagging every file with the same extension so users can see just how much they stand to lose. New variants are going even deeper: Tech2 detailed the use of TelsaCrypt to lock gaming files and force players to pay big money if they want to recover their saved games or online accounts.

There’s also JIGSAW, which takes its name from the villain of the “Saw” movie franchise. When users are infected, the malware explains that it “wants to play a game” and claims that in addition to locking down files, it will also send a copy of user data to all email contacts, in effect airing any digital dirty laundry.

Bottom line? Zepto is a lukewarm version of ransomware hot water. Attackers are putting users on notice and pulling out all the stops to incite fear and prompt payment.

More from

Remote access risks on the rise with CVE-2024-1708 and CVE-2024-1709

4 min read - On February 19, ConnectWise reported two vulnerabilities in its ScreenConnect product, CVE-2024-1708 and 1709. The first is an authentication bypass vulnerability, and the second is a path traversal vulnerability. Both made it possible for attackers to bypass authentication processes and execute remote code.While ConnectWise initially reported that the vulnerabilities had proof-of-concept but hadn’t been spotted in the wild, reports from customers quickly made it clear that hackers were actively exploring both flaws. As a result, the company created patches for…

Evolving red teaming for AI environments

2 min read - As AI becomes more ingrained in businesses and daily life, the importance of security grows more paramount. In fact, according to the IBM Institute for Business Value, 96% of executives say adopting generative AI (GenAI) makes a security breach likely in their organization in the next three years. Whether it’s a model performing unintended actions, generating misleading or harmful responses or revealing sensitive information, in the AI era security can no longer be an afterthought to innovation.AI red teaming is emerging…

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today