Ransomware as a Service
isc.sans.edu
isc.sans.edu
That's just a tor tunnel, IP and location doesn't matter.
Though it does make me think that it would be a good trick to offer this 'service', but then keep all the proceeds (everyone gets the same ransomware download). Maybe less profitable on the long term though.
Surely antivirus are not just trying to match the SHA1 of executables with SHA1 of known virus/malware, otherwise it would be trivial to bypass them.
I'm guessing those kind of approaches have largely gone away, being replaced with signatures that are hopefully fuzzier than a wholesale cryptographic hash, but still essentially only catching things after the fact, which works well with subscription business models.
I find this kind of interesting. I've seen reports on other malware/virus stuff written in Go recently. I wonder if this is because the ability to cross compile with Go is pretty painless? Or is it because the language is fairly approachable but still allows you to dig a bit "deeper" if you need to?
But maybe…
https://trends.google.com/trends/explore?q=python#GEO_MAP
https://trends.google.com/trends/explore?q=java#GEO_MAP
https://trends.google.com/trends/explore?q=javascript#GEO_MA...
https://trends.google.com/trends/explore?q=Kotlin#GEO_MAP
https://trends.google.com/trends/explore?q=lisp#GEO_MAP
My guess is that:
1. China blocks Google
2. Technical users in China use VPN to circumvent said block, while non-technical users switch to something else
3. Technical users search for programming language terms a lot
4. Thus the normalized ratio of (programming language search queries) / (total search queries) is a lot higher in China compared to other countries where Google isn't blocked
The list of countries where spyware is written intersected with golang popularity to me is actually a rough one, measuring languages' regional popularity always seems fraught.
Creating a ransomware is indeed not a very nice thing to do, but IMO the ones that deserve the most to be called "bad guys" are the ones that actually spread the binary (so, the ones that keep the other 90%)
We just like the marching, and the boots, and the hats.
I guess some people will argue that releasing ransomware will make software developers study the different types of attacks, so they increase security in computer systems.
Like if drinking poison builds up immunity, you don't get a free pass to feed people poison because of it. If you did, then the immunity goal doesn't matter because everyone would be poisoned to death first.
They used to take 20% 'commission'.