Vidar & Grandcrab will steal your wallet and lock you out!

Data theft and ransomware double whammy discovered, in short it will search for files containing personal information, send to C&C servers then just for good measure encrypt your machine so you get robbed then locked out! Not surprised these two methods have been combined, it had me wondering why it took so long for someone to combine the two, full blurb below:


The software nasty, bestowed the moniker Vidar combines the GandCrab ransomware with parts of the Arkei data-harvesting trojan to create a two-pronged attack that, on infected Windows PCs, first copies documents to outside servers, then locks away that personal information with a ransom demand.

According to Malwarebytes researcher Jerome Segura, the infection has been spreading in the wild via malicious advertising being piped into torrent and video streaming sites. The poisoned ads redirect users to a server hosting two exploit kits, Fallout EK and GrandSoft EK, which try to worm their way onto the target’s computer.

Should the exploit kit succeed in breaking in, it launches the data-stealing component of the infection. Segura said that the data-slurper, which looks to lift things like payment card numbers, site passwords, and cryptocoin wallets, is easy to mistake for the Arkei malware.

“Upon closer look, while the sample did share a lot of similarities with Arkei (including network events), it was actually a newer and, at the time, not yet publicly described piece of malware now identified as Vidar,” Segura explained.

After looking to scrape whatever valuable data it can find from the victim’s machine, the Vidar infection then dials up a control server and launches its second phase: the Gandcrab ransomware.

If the Vidar infection has been set up to give out the ransomware, the victim’s machine will then be locked off and the wallpaper changed to a notification on how to pay in order to get the files unencrypted.

Segura’s says the entire process, from loading up the malicious add to stealing the data and encrypting all of the victim’s files, takes roughly one minute to complete. The researcher suspects that, in this case, Vidar is using the ransomware as cover for its data-harvesting components.

The idea is that the victim will be so concerned with cleaning up the Gandcrab malware infection that they won’t notice the malware was also lifting their passwords, payment card numbers, and unique system configuration information.

“Threat actors can use ransomware for a variety of reasons within their playbook. It could be, for instance, a simple decoy where the real goal is to irreversibly corrupt systems without any way to recover lost data,” Segura said.

“But as we see here, it can be coupled with other threats and used as a last payload when other resources have already been exhausted.”

Nasty stuff!


Published by virtuallyonit

The ramblings of a techie working in the IT industry, many topics discussed, many views......

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: