A ransomware-as-a-service program called FilesLocker is offering affiliates commissions of up to 75 percent on all revenue stolen from victims if they can drive enough traffic.

Details about FilesLocker were first posted on Twitter, but a subsequent investigation traced it to Chinese cybercrime forum on TOR, an anonymous online network. Written in C# and available in both Chinese and English, some of the features promoted in the forum include strong encryption, the ability to clear shadow volume copies and customization capabilities.

While FilesLocker is relatively unsophisticated in design, according to security researchers, it encrypts victims’ files through a private key, which is encrypted by an embedded public key. By scanning common system folders such as Documents and Pictures, the ransomware-as-a-service offering encrypts files with a .locked extension and then displays a note demanding 0.18 bitcoin as payment to a specific email address, along with an automatically generated victim ID for tracking purposes.

How Affiliates Qualify For FilesLocker Spoils

The developer behind FilesLocker stipulated that any interested affiliates should have a proven track record in distributing ransomware through phishing schemes or other methods, with a minimum of 10 infections a day. He or she also warned against uploading the program to any service that helps organizations automate the process of scanning for viruses and other security threats. While those who do particularly well can earn three-quarters of what’s gathered from victims, the program includes a base revenue share of 60 percent.

The practice of spreading ransomware through affiliates is becoming more common among cybercriminals. Back in August, for example, cybercriminals pitched a similar ransomware-as-a-service threat dubbed Princess Evolution to potential partners for the same 60 percent revenue share.

Containing Threats Like FilesLocker

While it’s common and natural to panic upon seeing a ransom note pop up on the screen, security leaders should train users to report such incidents as quickly as possible so they can minimize the potential spread of ransomware-as-a-service programs.

IBM Security’s “Ransomware Response Guide” advised security professionals to immediately disconnect any machine infected with ransomware from the corporate network, as well as any access to Wi-Fi or other services that could link back to the attacker.

Isolating a system can give the security team enough time to conduct a proper route cause analysis (RCA) to identify how the ransomware is being distributed, which may mean closing off email or other communication channels for at-risk employees. Since malware developers are starting to work as a team, their potential victims need to do the same.

Sources: BleepingComputer, Malware Hunter, Virus Total

More from

Did Brazil DSL Modem Attacks Change Device Security?

From 2011 to 2012, millions of Internet users in Brazil fell victim to a massive attack against vulnerable DSL modems. By configuring the modems remotely, attackers could redirect users to malicious domain name system (DNS) servers. Victims trying to visit popular websites (Google, Facebook) were instead directed to imposter sites. These rogue sites then installed malware on victims' computers. According to a report from Kaspersky Lab Expert Fabio Assolini citing statistics from Brazil's Computer Emergency Response Team, the attack ultimately…

Who Carries the Weight of a Cyberattack?

Almost immediately after a company discovers a data breach, the finger-pointing begins. Who is to blame? Most often, it is the chief information security officer (CISO) or chief security officer (CSO) because protecting the network infrastructure is their job. Heck, it is even in their job title: they are the security officer. Security is their responsibility. But is that fair – or even right? After all, the most common sources of data breaches and other cyber incidents are situations caused…

Transitioning to Quantum-Safe Encryption

With their vast increase in computing power, quantum computers promise to revolutionize many fields. Artificial intelligence, medicine and space exploration all benefit from this technological leap — but that power is also a double-edged sword. The risk is that threat actors could abuse quantum computers to break the key cryptographic algorithms we depend upon for the safety of our digital world. This poses a threat to a wide range of critical areas. Fortunately, alternate cryptographic algorithms that are safe against…

Securing Your SAP Environments: Going Beyond Access Control

Many large businesses run SAP to manage their business operations and their customer relations. Security has become an increasingly critical priority due to the ongoing digitalization of society and the new opportunities that attackers exploit to achieve a system breach. Recent attacks related to corrupt data, stealing personal information and escalating privileges for remote code execution all highlight the new and varied entry points threat actors have taken advantage of. Attackers with the appropriate skills could be able to exploit…