Previous All Posts Next

PureBasic-based Ransomware Discovered

Posted: November 14, 2019 to Cybersecurity.

Tags: Ransomware, Cryptocurrency, Bitcoin, Malware

PureLocker, an unusual form of ransomware that attacks enterprise servers, has gone undetected for some time but has recently been revealed by cybersecurity analysts at Intezer and IBM X-Force.  What makes PureLocker so unique is that it’s written in PureBasic programming language.  Malicious software written in PureBasic is difficult for most security systems to detect.  It is also transferable amid different platforms like Windows, Linux, and OS-X. Aimed to strike the most valuable databases, the attackers hold the victims’ servers hostage until ransom is paid, usually in six-figure amounts of dollars or bitcoin.  The decryption key is promised reward for payment.  Non-payment of the fee within seven days threatens complete destruction of the decryption key, rendering the entire server’s critical data useless. According to Michael Kajilot, a security researcher at Intezer, there is no current figure on the number of victims affected by the PureLocker campaign.  Both Intezer and IBM X-Force have confirmed the campaign is active and being offered as a bespoke tool which limits criminal use to only those who can afford its dark web hefty price tag.  Cobalt Gang and FIN6 have launched previous campaigns with similar coding, and PureLocker does contain strings from ‘more_eggs’ backdoor malware.  Though the exact delivery method for PureLocker remains uncertain, its similarity with the ‘more_eggs’ malware suggesting phishing emails may be the entry point.
Craig Petronella
Craig Petronella
CEO & Founder, Petronella Technology Group | CMMC Registered Practitioner

Craig Petronella is a cybersecurity expert with over 24 years of experience protecting businesses from cyber threats. As founder of Petronella Technology Group, he has helped over 2,500 organizations strengthen their security posture, achieve compliance, and respond to incidents.

Related Service
Protect Your Business with Our Cybersecurity Services

Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.

Explore Cybersecurity Services
Previous All Posts Next