Ransomware ‘M.O.R.E’ Emerges on Dark Web: Threatens Windows, Mac, Linux Users

The code snippet provided in the post appears to be a PowerShell script, showcasing its capability to interact with files.

A new threat has emerged on the dark web, promising to target victims across multiple operating systems. Dubbed M.O.R.E (Multi OS Ransomware Executable), this dark web tool boasts native compatibility with various operating systems, including Windows, Mac OS, and Linux. The actor behind this multi OS ransomware claims it to be a game-changer for hacker groups.

According to the seller’s post timestamped at 02:49 AM on Wednesday, February 14, 2024, M.O.R.E offers swift encryption using advanced algorithms like RSA/Chacha20Poly1305.

It can crawl through systems and encrypt or decrypt hefty 1024 MB files in a mere 4 seconds. The dynamic multi-threading feature ensures efficient performance across a spectrum of machines, from low-end to high-end systems.

M.O.R.E: Multi OS Ransomware Executable: The New Dark Web Tool

Source: Daily Dark Web on X

The code snippet provided in the post appears to be a PowerShell script, showcasing its capability to interact with files. The snippet PowerShell script reads the first 15 lines of a file located at “TestFolder/file.txt” using the Get-Content cmdlet. 

However, the content displayed seems to be a jumble of characters and symbols, hinting at possible encryption or corruption. While the exact function of this script remains unclear, it highlights the potential threat posed by M.O.R.E.

Multi-OS ransomware, exemplified by tools like M.O.R.E, represents an evolution in cyber threats. Unlike traditional ransomware that targets specific operating systems, this new breed can infiltrate and encrypt files across different platforms simultaneously.

This capability opens up avenues for cybercriminals to unleash widespread chaos and demand hefty ransoms from victims.

Recent Multiple OS Threats: Ransomware and RATs

One such example of multi-OS malware is SysJoker RAT, as highlighted in a VMware report from the previous year. SysJoker RAT, designed to target Windows, Linux, and macOS, demonstrates the potency of cross-platform malware. By leveraging shared code across multiple platforms, attackers can execute commands remotely and deploy additional malicious payloads with ease.

Moreover, last year, India’s nodal agency for computer security-related threats issued a warning to citizens and organizations regarding the emergence of Akira ransomware, a cross OS threat targeting organizations around the globe.

The Union government’s Computer Emergency Response Team-India (CERT-In) issued the critical advisory, stating that the ransomware targeted both Windows and Linux-based operating systems. 

The agency informed that the group responsible for the ransomware compromised users via VPN services, particularly when multi-factor authentication wasn’t enabled. Additionally, they deceived users through tools such as AnyDesk, WinRAR, and PC Hunter, to download benign-looking files. 

Similarly other malware, RATs, and ransomware can infect multiple operating systems (OS), although they typically target a specific one known to have vulnerabilities.

It accomplishes this by detecting the OS first and then deploying its payload through various wrappers such as PowerShell or Linux bash scripts. 

These scripts download the malware into temporary storage and execute it. Additionally, the prevalence of Python or Java installations across systems provides a universal medium for malware interpretation and execution.

Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

View Comments

  • You are feeble-minded; it is not a PowerShell script; if you can read, it is programmed in Golang. I've used PowerShell to demonstrate the file size and the contents before and after, and with the Measure Command, measure the time it takes to execute M.O.R.E.

Recent Posts

Suisun City Declares Emergency After Cyberattack Disrupts Systems

Suisun City Emergency follows a cyberattack that shut down the city’s IT network, disrupting police, fire and 911 communications.

5 hours ago

AI Agent Exploits Gym System Vulnerability, Cancels Waitlist Booking in Australia

An AI agent exploited a gym system vulnerability in Australia, booked classes months ahead and cancelled another user's reservation.

6 hours ago

Ransomware Kingpin Gets 16 Years for Global Cyberattacks

The Justice Department’s Office of International Affairs provided substantial assistance with Silnikau’s extradition and the collection of evidence.

6 hours ago

Levi Strauss Hit by Cyberattack, Corporate Files Accessed

The Levi Strauss cyberattack comes as several major retailers have reported cybersecurity incidents involving their own systems or third-party service…

8 hours ago

The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks

This week's roundup covers Qilin ransomware, government database breaches, and third-party cyberattacks reshaping today's threat landscape.

3 days ago

Point72 Among Major Hedge Funds Targeted in Cyberattack on Wall Street Through Voice Phishing Campaign

Point72 and other major hedge funds faced a cyberattack on Wall Street using voice phishing, highlighting rising AI-driven social engineering…

3 days ago

This website uses cookies. By continuing to use this website you are giving consent to cookies being used.

Read More