Site icon TheCyberThrone

GoodWill Ransomware Rampant with a Cause

Advertisements

Ransomware attacks are unfortunately now very common. Most attackers demand that their victims pay them using bitcoins to get their files back. However, one group has adopted a rather unique approach. The GoodWill ransomware group insists that its victims perform and document acts of service.

GoodWill ransomware was identified by CloudSEK researchers in March 2022. As the name suggests, the operators are allegedly interested in promoting social justice rather than conventional financial reasons. CloudSEK researchers have been able to identify the following features of GoodWill:

Advertisements

Action Items for the victims are as follows

  1. Victims must first directly donate clothes and/or blankets to “needy people on the side of the road.” They then are required to post a video or photo of them giving the clothes and blankets on Facebook, Instagram, and WhatsApp and screenshot their post and email it to the GoodWill Ransomware group. The group hopes that the social media posts will encourage others to aid the less fortunate and the posts all keep the victims accountable.
  2. Victims must then take out at least five “poor” children under the age of thirteen to dinner at a fast-food chain such as Dominos or KFC. They are tasked with being kind to the children during the dinner. They need to take a selfie of themselves with their children, post it on social media, and send a snapshot of their social media post and their dinner bill to the GoodWill ransomware group
  3. Victims must visit a hospital and pay for the medical treatment of those in need. Victims are encouraged to take selfies with those they are helping and must send a recording of their conversations to the GoodWill ransomware group.
  4. Victims are tasked with writing a post on social media about how they are transforming “into a kind human being by becoming a victim of ransomware called GoodWill.” They must once again send a screenshot of their post to the group to verify its authenticity. The GoodWill ransomware group will then provide the victims with a decryption key and leave them be.

The research team has traced them to an Indian IT and cybersecurity company that provides “end-to-end managed security services.” Now, it is unclear how the ransomware is spread, but what is clear is that the ransomware group’s motivations are unusual.

These are GoodWill ransomware tunnels that are also subdomains of Ngrok.io:

Advertisements

Indicators Of Compromise

Exit mobile version