Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Ransom32 Is a JavaScript-Based Ransomware That Uses Node.js to Infect Users
Softpedia ^ | 3 Jan 2016, 14:54 GMT | Catalin Cimpanu

Posted on 01/03/2016 11:16:43 PM PST by Utilizer

A new type of ransomware has been spotted, the first of its kind, a ransomware that uses JavaScript to infect its users, being coded on top of the NW.js platform.

NW.js, formerly known as Node-WebKit, is a powerful platform that allows developers to create desktop applications via Node.js modules. The platform lets programmers use JavaScript in the same way, and with the same power and reach inside the underlying operating system's guts, as other more powerful languages like C++, Delphi, Java, ActionScript, and C#.

If the name hasn't tipped you off yet, NW.js uses a stripped down version of WebKit, the same layout engine used in Chrome, Safari, and Opera, but without many of its limitations. While browsers limit what JavaScript code can do, NW.js removes these limits and allows JS developers to interact with the OS itself.

NW.js can run on all three major operating systems, meaning that ransomware coded to work on top of it would theoretically be able to target all operating systems at once.

(Excerpt) Read more at news.softpedia.com ...


TOPICS: Computers/Internet
KEYWORDS: internet; javaransomware; javascript; malware; ransomware; security; virus; windows; windows10; windows8; windowspinglist; windowsxp
Navigation: use the links below to view more comments.
first 1-2021-4041 next last
A multi-OS ransomware threat?
1 posted on 01/03/2016 11:16:43 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: dayglored

Ping...


2 posted on 01/03/2016 11:54:55 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Dunno if this of interest to you, mate, but just in case... ping.


3 posted on 01/03/2016 11:55:39 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Well what do you know, a use for bitcoins other than buying drugs. To pay off your ransomware virus fees.


4 posted on 01/04/2016 12:28:07 AM PST by LowOiL ("Let us do evil that good may come"? ....condemnation is just - Romans 3:8)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer; ShadowAce; ThunderSleeps; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; ...
Aw, THIT! Another means of invading all of our platforms, Windows, Macs, Android, and iOS utilizing JAVA script. . . which can work through a browser all the way into the OS. NOT GOOD, AT ALL. Damn! -- PING!

Pinging Shadow Ace and Thunder Sleeps for their lists.


SECURITY
Ping!

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

5 posted on 01/04/2016 12:31:08 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 3 | View Replies]

TURNING OFF JAVASCRIPT

In iOS. . . Safari

Go to Settings/ Safari / Advanced. Turn off JavaScript.

In OS X Safari

Open Safari

Click on Safari Prefernces

Select Security Tab

Uncheck "Enable JavaScript"

Close Preferences pane.

In Windows Safari

Open Windows Safari

Click on the Tools Button icon Tools Button at the top-right of the app window

Click on the Preferences menu item

Click on the Security icon

Un-check the Enable JavaScript option.

Close the Preferences window and restart Safari.


6 posted on 01/04/2016 12:50:55 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Seriously? Disable javascript? What, are we back to HTML 2.0?


7 posted on 01/04/2016 1:04:33 AM PST by Jeff Chandler (I shot Schroedinger's cat with Chekhov's gun.)
[ Post Reply | Private Reply | To 6 | View Replies]

Turning JavaScript off in Windows Chrome:

Right click the Google Chrome icon in your desktop, then click Properties.

2. Click Shortcut tab.

3. Add -disable-javascript parameter in the Target field.

4. Click the OK button.,


Turning JavaScript off in Apple OS X Chrome:

Go to this link and follow the steps shown to turn off JavaScript in Apple OS X


8 posted on 01/04/2016 1:05:41 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Jeff Chandler
Seriously? Disable javascript? What, are we back to HTML 2.0?

It may be necessary until they get a handle on blocking this All Platform Ransomeware exploit.

9 posted on 01/04/2016 1:08:18 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Swordmaker

You are telling everyone to browse without javascript?


10 posted on 01/04/2016 1:08:57 AM PST by Jeff Chandler (I shot Schroedinger's cat with Chekhov's gun.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Swordmaker

Don’t worry, Dude. Apple products are immune to exploits, aren’t they? I mean, you don’t need an antivirus program, so don’t worry.


11 posted on 01/04/2016 1:11:11 AM PST by Jeff Chandler (I shot Schroedinger's cat with Chekhov's gun.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Utilizer

Wouldn’t it be safer to just not run as administrator ( which you should never do - always run with non admin privileges ) in the first place instead of disabling javascript ?


12 posted on 01/04/2016 1:13:10 AM PST by TheCipher (Suppose you were an idiot and suppose you were a member of Congress. But I repeat myself. Mark Twain)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer
Currently, only Windows machines have been infected, but we may be one update cycle away from seeing the first truly cross-OS ransomware family.

13 posted on 01/04/2016 1:13:50 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

You run node server-side, well. It ain’t rails or jetty, that’s for sure.

Let alone IIS.


14 posted on 01/04/2016 1:17:56 AM PST by some tech guy (Stop trying to help, Obama)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TheCipher
Wouldn’t it be safer to just not run as administrator

And use an antivirus program.

Oh, Mac doesn't need an antivirus program. Just browse without JavaScript.

15 posted on 01/04/2016 1:17:57 AM PST by Jeff Chandler (I shot Schroedinger's cat with Chekhov's gun.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Jeff Chandler
You are telling everyone to browse without javascript?

Yes, I am. Currently, this exploit is only in the wild for Windows, but it works through browsers, and will not give any privilege escalation, but it could steal user's passwords, data, and other critical information.

Even though on a Mac the Browser operates in a sandbox, the browser can call passwords from the keychain and auto fill user data into fields. This exploit could conceivably cause your browser to navigate to a malicious website with appropriate fields to be auto-filled, do so, then call passwords for commonly visited websites in your bookmarks and harvest them.

16 posted on 01/04/2016 1:23:02 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 10 | View Replies]

To: TheCipher
Wouldn’t it be safer to just not run as administrator ( which you should never do - always run with non admin privileges ) in the first place instead of disabling javascript ?

Always. But this doesn't matter for what it does. It works through the browsers using JavaScript and it isn't intended to install malware. It is a script the browsers are supposed to run. . . But this one can do things other scripts aren't permitted to do.

17 posted on 01/04/2016 1:29:33 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Swordmaker

Turn off javascript? Might as well turn off css.


18 posted on 01/04/2016 1:38:33 AM PST by Jeff Chandler (I shot Schroedinger's cat with Chekhov's gun.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Swordmaker

Hey, I don’t suppose this is the virus which infected the FreeRepublic servers and made it put out weird characters?


19 posted on 01/04/2016 1:40:06 AM PST by Jeff Chandler (I shot Schroedinger's cat with Chekhov's gun.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Jeff Chandler
Hey, I don’t suppose this is the virus which infected the FreeRepublic servers and made it put out weird characters?

Would it be that simple. Sadly, it's not.

20 posted on 01/04/2016 1:47:10 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson