August 21, 2018 By Shane Schick 2 min read

The creators of a ransomware-as-a-service (RaaS) threat dubbed Princess Evolution are looking for affiliates to spread their exploit kit in exchange for more than half of what’s stolen.

Trend Micro discovered Princess Evolution during an investigation into the traffic stream of a malvertising campaign on the underground Tor network that stemmed from the Rig exploit kit. Meanwhile, an advertisement that has been running in a cybercriminal forum since late last month is offering affiliates 60 percent of any proceeds from the RaaS threat, which was developed from the Princess Locker ransomware that was discovered in 2016.

Why Security Teams Should Be Concerned About the Evolution of Ransomware-as-a-Service

Unlike Princess Locker, Princess Evolution’s command-and-control (C&C) server is based on the user datagram protocol (UDP), which the researchers said works more quickly and efficiently than the more traditional HTTP.

Once installed on a device, Princess Evolution uses a mixture of unrelated numbers as the extensions for the victim’s encrypted files. Re-establishing control of the device costs 0.12 bitcoin, according to the ransom note that that appears on victims’ machines.

While some victims might not download the RaaS threat, the researchers noted that the malvertising campaign that is being used to spread Princess Evolution contains a backup plan of sorts. Anyone who clicks on the malicious ad, which contains CoinHive, will enable cybercriminals to divert the device’s computing resources to mine for cryptocurrencies. The malvertisements are placed on compromised sites that may take advantage of vulnerabilities on a victim’s device without his or her knowledge.

How the DNS Sinkholes Can Help Reduce the Threat of RaaS

There’s no known way to recover files once Princess Evolution has infected a device, so chief information security officers (CISOs) and their teams should focus on ensuring that employees don’t become victims in the first place.

While organizations should always keep track of blacklisted IP addresses, filter websites based on reputation and block potentially dangerous domains, IBM experts also suggest using what’s called a “sinkhole capability” for domain name servers (DNSs). That means if someone attempts to visit or accidentally stumbles upon a blocked site, the sinkhole will alert the security team, inform the potential victim, and send the IP address and domain to an internal server before it gets out of hand.

Security professionals should also block all URL- and IP-based indicators of compromise (IoCs) at the firewall, update all antivirus software, ensure that third-party vendors have coverage for this RaaS campaign, and search within the organization’s IT environment and email systems for existing signs of the IoCs listed in this threat advisory from IBM X-Force Exchange.

Source: Trend Micro

More from

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today