April 14, 2016 By Larry Loeb 2 min read

Researchers from the anti-malware and Internet security firm Malwarebytes reported finding a possible link between the Rokku ransomware and Chimera’s file-encrypting capabilities.

Rokku allows victims to scan a QR code to obtain information on how to make the ransom payment. The Chimera ransomware, which was discovered in December 2015, threatened to post victims’ files and credentials online unless they paid the ransom. However, the threatened results never came to fruition, making Chimera social engineering malware that functionally operated in reverse.

Rokku Ransomware Looks Familiar

Researchers at Malwarebytes found that the dynamic link library (DLL) files containing the core malicious actions in both the Rokku and Chimera ransomware depended on the ReflectiveLoader function. This function is used for reflective DLL injection, which loads a library from memory into a host process. This is similar to a shellcode since the DLL is self-contained and automatically loads all its dependencies.

The security firm noted that Rokku dropped ransom notes in two formats: HTML and TXT. It then substituted files with their encrypted counterparts. Because Rokku doesn’t retrieve keys from a server, the encryption process can be executed offline.

The ransom note asks a victim to upload one encrypted file. All the necessary data is derived from the uploaded file for a single demonstration of decryption.

Rokku uses two types of cryptographic algorithms: asymmetric for the root key and symmetric for the keys of individual files. Researchers explained this further, stating that the individual random key is applied to file content before being encrypted and stored with the hostage files.

There are other similarities between Rokku and Chimera. For example, cryptography is implemented locally for both, not via API calls. Both also have an external decryptor that can be downloaded before paying the ransom as a demonstration of validity.

Different Strokes

There are distinctions between the two, as well. They use differing methods of communicating with victims: Chimera uses bitmessage, while Rokku leverages a Tor website like most other ransomware. Additionally, Chimera requires an Internet connection to work, but Rokku is fully independent from a command-and-control server.

The similarities between the two types of ransomware leads experts to believe that they may be produced by the same authors using the same schema, even though the two have differing purposes. However, the best practices for staying clear of ransomware still apply to each of these exploits.

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today