New RAA Ransomware Strain Created Entirely Using Javascript

Stu Sjouwerman | Jun 18, 2016

Larry Abrams, who runs Bleepingcomputer was first to report on a new strain of ransomware called RAA. The criminal coders took the somewhat unusual step of writing the whole thing in JavaScript making it more damaging in certain situations, and also install the Pony password stealer for good measure.

Larry wrote that it is being distributed by email through attachments that pretend to be a regular Doc file. Since JavaScript itself does not have crypto functions, the bad guys use the CryptoJS library which allows them to use AES encryption to lock up their victims' files. Here is how the fake attachment looks:

RAA Ransomware Fake Attachment

Opening the attachment does not visibly do anything, but appears to the victim as a corrupted file. However, back at the ranch it is busy as a beaver doing its dirty work in the background, including deleting the Windows Volume Shadow Copy so the encrypted files cannot be recovered. 

The RAA strain is set to be persistent so that the ransomware runs every time Windows is rebooted and even encrypts any new files created since the most recent login. Ransom32 is another strain developed in JavaScript, however RAA is different in that it is a standard JS file and not delivered via an executable.

Disabling the Windows Script Host will stop a JS file from executing outside of the browser, Javascript will still function within a web browser. See the full technical detail over at Larry's post.


Ransomware Hostage Rescue Manual

Get the most complete Ransomware Manual packed with actionable info that you need to have to prevent infections, and what to do when you are hit with ransomware.

Download Here

Topics: Ransomware

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.