December 5, 2017 By Shane Schick 2 min read

A pair of ransomware variants called Vortex and Bugware are encrypting victims’ files by using open source repositories and targeting .NET users, researchers warned. Based on an investigation published by Zscaler, those affected by the two families are being hit with demands that, in the case of Vortex, start at $100 and double within less than a week.

The researchers discovered live instances of the attacks using spam emails and links laden with malware. While Vortex was designed with open source encryption tool AESxWin, Bugware makes use of Hidden Tear code, a ransomware-like crypter sample.

A Vicious One-Two Ransomware Punch

According to SecurityWeek, the fraudsters behind Bugware masquerade as a Latin American utilities firm called GAS INFORMATICA LTDA. The ransomware displays a certificate that insists on a payment of 1,000 Brazilian real. Bugware also reinstates itself using a key whenever the victim logs on, stealing removable drives and other network files.

Vortex, meanwhile, uses a registry entry to stay active on a victim’s machine and even deletes backup versions of files the that victim may attempt to recover by reverting the system to a pre-infection state. Audio and video files are encrypted along with more traditional text files.

Although there are several differences between the two ransomware strains — Vortex is written in Polish while Bugware sends ransom messages in Portuguese, for example — SC Magazine reported that both use the Confuser packer and Microsoft Intermediate Language (MISL) for compilation purposes. Bugware also appears to have emerged just two months ago, while Vortex may have been active since March.

Forcing Victims to Pay Up

Both ransomware variants go to great lengths to minimize victims’ odds of retrieving their data without handing over money. As Virus Guides noted, files stolen by Vortex can only be decrypted if users know the password associated with AESxWin at the time of the attack. Bugware hides everything it can in a registry, including an RSA public key, AES key and even a base64-encoded key.

Taken together, these threats illustrate just how much damage cybercriminals with the right know-how can do with open source repositories.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today