New ransomware written in JavaScript discovered
scmagazine.com
scmagazine.com
In short, Windows completely exposes its filesystem through ActiveX and WScript, skipping the need to package Node for filesystem access. Then bundle native JS crypto along with some nasty string-encoded binaries, and you've got everything you need to hold a PC hostage.
Makes me wonder if there's a way to commit such evils with AppleScript and/or JavaScriptCore...
[0]: https://gist.github.com/Antelox/020c727e1917bd018441cb6425ca...
[1]: https://reaqta.com/2016/06/raa-ransomware-delivering-pony/
> Most randomly generated URLs look like this: G1XeD4SwlHReDA. We thought it would be fun to do it differently. Our URLs follow the nomenclature: AdjectiveAdjectiveAnimal This is enough to give us a namespace of billions, while also letting humans write them easier. You’re welcome! https://gfycat.com/about
In fact, I bet this "exploit" doesn't work on a properly-secured box with UAC on where a user is not running as a local admin, at least not for the part about Volume Shadow Copy.
It's a shame because I personally like CScript/WScript, it's the little scripting engine that could. Unfortunately, the Windows security model is too haphazard to let something like this free to run.
As a sysadmin myself we have set all computers to open .js files with notepad by default (rather than the Windows Scripting Engine) so they will not execute if opened accidentally.
You can even add your own executable formats to do stuff like running Java class files by typing `./main.class`: https://www.kernel.org/doc/Documentation/binfmt_misc.txt
I never looked at what its payload was. It's good to see that js viruses have also made their way to modern coding standards.
TIL that in Windows .js files can be executed outside of the browser...
https://gist.github.com/Antelox/020c727e1917bd018441cb6425ca...
Further, my university (University of Calgary) was recently hit by ransomware, and I have heard that some Calgary companies have also been hit by ransomware in the last 4-6 weeks. If the attack is this prevalent, and arguably this easy for non-expert users to accidentally execute over a whole network, I think we need to seriously consider how we train our users and what kinds of default permissions we allow.
There is no such thing as low-level JS.
Edit: For those who don't believe that JS can't be low-level, please see Wikipedia's definition of "low-level programming language"[1]:
"a programming language that provides little or no abstraction from a computer's instruction set architecture—commands or functions in the language map closely to processor instructions"
If you know literally anything about JavaScript, how it runs, or how processors run, you'll know that JS is not even in the ballpark of "low-level".
Perhaps the parent comment was referring to "JavaScript without frameworks, third-party libraries, or heavy abstractions," which is still not exactly a complex or mystifying arena.
1. https://en.wikipedia.org/wiki/Low-level_programming_language
And as you correctly note, the ransomware code does not come close to qualifying as "low-level".
Huh.
` npm install `
` pod install `
And the likes.
You know, third party services which we wholeheartedly trust and let them execute whatever they download from github on our development machines.
Ransomware is very close to being a perfect crime and I don't see why people would ever stop doing it.
Expect it to become really widespread and evolved.
That being said, if you are developing and deploying ransomware, then you are doing a very wrong thing, spiritually.
You may not believe in karma, because it's convenient to you, but the message from our ancestors has always been this - all the shit that you cause in life is going to come back to you OR your children in one form or another - multiplied. So just don't.
Almost all worldviews share a similar idea, but that does not make it a proven fact. Ultimately, they are all premised on a omniscient and vindictive entity (either explicitly or implicitly). I'm of the opinion that these views originate more from a desire to soothe victims than to discourage offenders.
We should do better than vague threats to improve society.