#1 Trending Cybersecurity News & Magazine
Monday, September 18, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily Dark Web News

NoEscape Ransomware-as-a-Service (RaaS): Triple-Extortion Affiliate Program Unveiled

What sets NoEscape apart is its claim of being a C++-based ransomware developed entirely in-house, without relying on third-party resources or source codes. 

Editorial by Editorial
June 3, 2023
in Dark Web News, Firewall Daily
0
NoEscape Ransomware-as-a-Service (RaaS)
705
SHARES
3.9k
VIEWS
Share on LinkedInShare on Twitter

A new threat actor has emerged on the underground forums. The Cyble Research & Intelligence Labs (CRIL) uncovered NoEscape Ransomware-as-a-Service (RaaS). This program surfaced on a cybercrime forum in late May 2023 and actively sought affiliates to join it.

What sets NoEscape apart is its claim of being a C++-based ransomware developed entirely in-house, without relying on third-party resources or source codes. 

You might also like

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

The Three Trends to Watch in the Growing Threat Landscape

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

This self-sufficiency gives the operators and affiliates unprecedented control over their malicious activities.

Notably, NoEscape Ransomware-as-a-Service (RaaS)utilizes a triple-extortion technique to maximize its leverage when extorting victims.

What’s unique about NoEscape Ransomware-as-a-Service (RaaS)?

NoEscape Ransomware-as-a-Service

CRIL analyzed the intricate workings of the ‘NoEscape’ Ransomware-as-a-Service (RaaS) program, an exclusive platform vowing to empower blackmail campaigns by leveraging a cutting-edge, homegrown ransomware variant. 

Upon analyzes, the researchers made the following observations:

Encryption algorithms

The ransomware used in the NoEscape Ransomware-as-a-Service (RaaS) employs a combination of ChaCha20 and RSA encryption algorithms.

This hybrid-cryptography approach, often utilized by sophisticated ransomware groups, ensures the encryption of files and the protection of encryption keys.

The ransomware encrypts all ChaCha20 keys with a global ChaCha20 key, which is then encrypted with an RSA-2048 public key.

Windows Safe Mode compatibility

The NoEscape Ransomware-as-a-Service (RaaS) campaign supports Windows Safe Mode, allowing the ransomware to turn off endpoint security products and encrypt files by rebooting compromised systems.

By employing this method, the ransomware achieves high efficacy and impact during encryption.

Lateral movement and evasion techniques

NoEscape Ransomware-as-a-Service (RaaS) utilizes asynchronous LAN scanning to identify Distributed File System (DFS) and Server Message Block (SMB) protocols.

This capability enables lateral movement, persistence, and evasion, making it harder for security solutions to detect and mitigate the ransomware’s activities.

Shared encryption

The ransomware employs shared encryption, using a single key to encrypt all files on a network or system instead of assigning a unique key to each file.

This approach allows attackers to expedite the encryption process for large datasets. However, victims can still decrypt their encrypted data in such cases.

The anonymity of Bitcoin transactions

The NoEscape Ransomware-as-a-Service (RaaS) incorporates an integrated service to maintain the anonymity of Bitcoin transactions. However, the specific method employed to prevent tracing Bitcoin transactions remains undisclosed.

Compatibility and configurability

The ransomware employed by the NoEscape Ransomware-as-a-Service (RaaS) hackers is compatible with a wide range of systems, including Windows Desktop XP – 11, Windows Server 2003 – 2022, Linux distributions (such as Ubuntu and Debian-based), and VMware ESXi.

It also offers configurable mode settings, such as Ignore, Fast, Strong, and Balanced, allowing operators to customize the encryption process.

Extensive features for operations

The NoEscape ransomware provides a comprehensive set of features to its affiliates. The administrator’s panel, hosted on Tor, offers automated functionalities.

A fully automated Leak website is also available on Tor. Affiliates can create private chats for secret communication with recovery companies, generate builds with different settings and one key, build their chat support, and access 24/7 support for queries.

The ransomware also includes prompt messages to coerce victims into responding.

Triple-extortion technique

Once NoEscape ransomware infiltrates a network, it spreads laterally, encrypting data and demanding a ransom for its release.

If the ransom is not paid, the operators may sell the stolen data or publish it in public blogs and online forums. This triple-extortion technique adds extra pressure on victims to comply with the attackers’ demands.

Additional extortion services

Notably, the NoEscape Ransomware-as-a-Service (RaaS) operators offer an additional service for DDoS/Spam attacks at a price of USD 500,000. This service provides cybercriminals with another method to threaten and coerce targeted companies into paying the demanded ransom.

Origin and affiliates

The exact origin of NoEscape Ransomware-as-a-Service (RaaS) remains undisclosed. However, certain conditions enforced by the operators prohibit affiliates from targeting entities in the Commonwealth of Independent States (CIS) countries, hinting at a possible connection to Russia or the CIS.

Profit-sharing model

The profit-sharing model of NoEscape Ransomware-as-a-Service (RaaS) incentivizes affiliates based on the payout achieved through their malicious activities.

Affiliates receive 80% of the profit if the payout equals or exceeds USD 1 million, 85% for a payout equal to or exceeding USD 3 million, and 90% for payouts exceeding USD 3 million.

The NoEscape Ransomware-as-a-Service (RaaS) represents a dangerous evolution in cybercrime. 

Its robust technical capabilities, triple-extortion methodology, and attractive profit-sharing model make it appealing to cybercriminals seeking to maximize their illicit gains. 

The emergence of such sophisticated RaaS programs underscores the need for enhanced cybersecurity measures to protect organizations and individuals from falling victim to these malicious activities.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: NoEscape Ransomware-as-a-Service (RaaS)
Previous Post

SharpPanda APT Targets High-Level Government Officials From G20 Nations

Next Post

Billtrust Appoints Ankur Ahuja as SVP and Chief Information Security Officer

Editorial

Editorial

The Cyber Express is a publication that aims to provide the latest news and analysis about the information security industry. The news comes from a variety of sources and is updated regularly so that readers can stay up to date with the latest happenings in this rapidly growing field.

Related Posts

US Cybersecurity Regulations: Tracing the Past and Predicting the Future
Firewall Daily

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

by Vishwa Pandagle
September 17, 2023
threat landscape
Cyber Essentials

The Three Trends to Watch in the Growing Threat Landscape

by Editorial
September 17, 2023
Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

by Ashish Khaitan
September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

by Vishwa Pandagle
September 16, 2023
John Blackmon
Firewall Daily

Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

by Editorial
September 16, 2023
Next Post
Billtrust Appoints Ankur Ahuja

Billtrust Appoints Ankur Ahuja as SVP and Chief Information Security Officer

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

US Cybersecurity Regulations: Tracing the Past and Predicting the Future
Firewall Daily

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

September 17, 2023
threat landscape
Cyber Essentials

The Three Trends to Watch in the Growing Threat Landscape

September 17, 2023
Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

September 16, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance