Jokeroo Ransomware-as-a-Service
Jokeroo is a variant of the GandCrab ransomware, recently offered as a service on underground hacking forums and Twitter.
Summary
Jokeroo is a variant of the GandCrab ransomware, recently offered as a service on underground hacking forums and Twitter.
Affected platforms
The following platforms are known to be affected:
Threat details
Unlike most Ransomware-as-a-Service (RaaS) offerings, Jokeroo is marketed as a series of membership packages ranging from 90 to 600 USD, these packages give the subscriber access to the ransomware, payment server and a variable percentage of any earnings depending upon the chosen package.
At the time of publication, Jokeroo’s administrators are attempting to perform an exit scam by falsely claiming that their services have been seized by local law enforcement agencies. Despite this, it is likely several Jokeroo samples are available in the wild.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:47 pm