December 5, 2017 By Shane Schick 2 min read

A pair of ransomware variants called Vortex and Bugware are encrypting victims’ files by using open source repositories and targeting .NET users, researchers warned. Based on an investigation published by Zscaler, those affected by the two families are being hit with demands that, in the case of Vortex, start at $100 and double within less than a week.

The researchers discovered live instances of the attacks using spam emails and links laden with malware. While Vortex was designed with open source encryption tool AESxWin, Bugware makes use of Hidden Tear code, a ransomware-like crypter sample.

A Vicious One-Two Ransomware Punch

According to SecurityWeek, the fraudsters behind Bugware masquerade as a Latin American utilities firm called GAS INFORMATICA LTDA. The ransomware displays a certificate that insists on a payment of 1,000 Brazilian real. Bugware also reinstates itself using a key whenever the victim logs on, stealing removable drives and other network files.

Vortex, meanwhile, uses a registry entry to stay active on a victim’s machine and even deletes backup versions of files the that victim may attempt to recover by reverting the system to a pre-infection state. Audio and video files are encrypted along with more traditional text files.

Although there are several differences between the two ransomware strains — Vortex is written in Polish while Bugware sends ransom messages in Portuguese, for example — SC Magazine reported that both use the Confuser packer and Microsoft Intermediate Language (MISL) for compilation purposes. Bugware also appears to have emerged just two months ago, while Vortex may have been active since March.

Forcing Victims to Pay Up

Both ransomware variants go to great lengths to minimize victims’ odds of retrieving their data without handing over money. As Virus Guides noted, files stolen by Vortex can only be decrypted if users know the password associated with AESxWin at the time of the attack. Bugware hides everything it can in a registry, including an RSA public key, AES key and even a base64-encoded key.

Taken together, these threats illustrate just how much damage cybercriminals with the right know-how can do with open source repositories.

More from

Exploring the 2024 Worldwide Managed Detection and Response Vendor Assessment

3 min read - Research firm IDC recently released its 2024 Worldwide Managed Detection and Response Vendor Assessment, which both highlights leaders in the market and examines the evolution of MDR as a critical component of IT security infrastructure. Here are the key takeaways. The current state of MDR According to the assessment, “the MDR market has evolved extensively over the past couple of years. This should be seen as a positive movement as MDR providers have had to evolve to meet the growing…

Regulatory harmonization in OT-critical infrastructure faces hurdles

3 min read - In an effort to enhance cyber resilience across critical infrastructure, the Office of the National Cyber Director (ONCD) has recently released a summary of feedback from its 2023 Cybersecurity Regulatory Harmonization Request for Information (RFI). The responses reveal major concerns from critical infrastructure industries related to operational technology (OT), such as energy, transport and manufacturing. Their worries include the current fragmented regulatory landscape and difficulty adapting to new cyber regulations. The frustration appears to be unanimous. Meanwhile, the magnitude of…

Generative AI security requires a solid framework

4 min read - How many companies intentionally refuse to use AI to get their work done faster and more efficiently? Probably none: the advantages of AI are too great to deny.The benefits AI models offer to organizations are undeniable, especially for optimizing critical operations and outputs. However, generative AI also comes with risk. According to the IBM Institute for Business Value, 96% of executives say adopting generative AI makes a security breach likely in their organization within the next three years.CISA Director Jen…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today