Monday, March 4, 2024

Ransomware-as-a-Service – New Saturn Ransomware Available to Anyone For Free

Now any anyone can become a distributor of newly identified Saturn ransomware through the Ransomware as a Service affiliate program. To become a distributor of ransomware all you need is to signup in the RaaS portal download a copy and distribute it.

The Raas portal was detected and the Saturn ransomware Raas business model is different from other RaaS portal’s here distributor not required to pay any advance before using the ransomware binary.

RaaS economic business model that allows attackers to earn money without distributing the malware. Instead, they host their services in dark web and anyone can buy it and they can change their own modification such as ransom amount, ransom notes.

The users can download a file called stub from the Saturn RaaS portal and then embed the file into other files such as EXEs, Office, PDF, or other documents.

The ransomware can be distributed in any means Phishing Email, Email Attachments, Embedded Hyperlink, Drive by Infection and Websites & Downloads.

RaaS portal

Infected victims should pay ransom fees on Saturn payment portal and the distributor of the ransomware will get 70% of the total payment and 30% to Saturn creators.

Last Friday researchers from McAfee Labs detected RaaS portal with the same business model.Once the distributor successfully compromised the victims and if the victim paid the ransom amount then the 10% of ransom amount will be transferred into the original developer’s wallet and 90% to the distributor.

ESET says there is a temporary drop in the number of spikes that were observed when compared to the end of the last year.

Also Read Ransomware Attack Response and Mitigation Checklist

Without a doubt 2017 is the year of data breaches and ransomware, now attackers shifted their focus to crypto mining attacks by using victims resources. Starting from the year 2018 a number of Cryptomining Attacks launched to Mine Monero Cryptocurrency.

Final Notes

The ransomware is a turnkey business for some criminals, and victims still pay the ever-increasing demands for ransom, it’s become a billion-dollar industry that shows no signs of going away anytime soon.


Latest articles

New Silver SAML Attack Let Attackers Forge Any SAML Response To Entra ID

SolarWinds cyberattack was one of the largest attacks of the century in which attackers...

AI Worm Developed by Researchers Spreads Automatically Between AI Agents

Researchers have developed what they claim to be one of the first generative AI...

20 Million+ Cutout.Pro User Records Leaked On Hacking Forums

CutOut.Pro, an AI-powered photo and video editing platform, has reportedly suffered a data breach,...

CWE Version 4.14 Released: What’s New!

The Common Weakness Enumeration (CWE) project, a cornerstone in the cybersecurity landscape, has unveiled...

RisePro Stealer Attacks Windows Users Steals Sensitive Data

A new wave of cyber threats has emerged as the RisePro information stealer targets...

Golden Corral Restaurant Chain Hacked: 180,000+ Users’ Data Stolen

The Golden Corral Corporation, a popular American restaurant chain, has suffered a significant data...

CISA Warns Of Hackers Exploiting Multiple Flaws In Ivanti VPN

Threat actors target and abuse VPN flaws because VPNs are often used to secure...
Guru baran
Guru baran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Live Account Takeover Attack Simulation

Live Account Take Over Attack

Live Webinar on How do hackers bypass 2FA ,Detecting ATO attacks, A demo of credential stuffing, brute force and session jacking-based ATO attacks, Identifying attacks with behaviour-based analysis and Building custom protection for applications and APIs.

Related Articles