{"id":7299,"date":"2017-04-10T10:30:14","date_gmt":"2017-04-10T18:30:14","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/04\/10\/news-1090\/"},"modified":"2017-04-10T10:30:14","modified_gmt":"2017-04-10T18:30:14","slug":"news-1090","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/04\/10\/news-1090\/","title":{"rendered":"New ransomware demanded high score on anime-style shooter game not bitcoins"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/zapt0.staticworld.net\/images\/article\/2016\/04\/frustrated-computer-user-100657949-primary.idge.jpg\"\/><\/p>\n<p><strong>Credit to Author: Darlene Storm| Date: Mon, 10 Apr 2017 09:23:00 -0700<\/strong><\/p>\n<p>Never underestimate what a person can come up with when he or she is bored as was recently highlighted by the accidental release of a ransomware that required victims to reach an astronomically high score on an anime-style shooter game instead of paying an outrageous ransom in bitcoins.<\/p>\n<p>The Malware Hunter Team was <a href=\"https:\/\/twitter.com\/malwrhunterteam\/status\/850031671244193792\" target=\"_blank\">surprised<\/a> to discover Rensenware; they said the ransomware did not ask \u201cfor any money, but to play a game until you reach a score \u2013 and it\u2019s not a joke.\u201d<\/p>\n<p>Victims who wanted their files decrypted were required to score over 200 million points in the \u201clunatic\u201d level of the game <a href=\"https:\/\/en.touhouwiki.net\/wiki\/Undefined_Fantastic_Object\" target=\"_blank\"><em>TH12 ~ Undefined Fantastic Object<\/em><\/a>.<\/p>\n<p dir=\"ltr\" lang=\"en\">Found a surprising ransomware today: &#8220;rensenWare&#8221;.<br \/>Not asks for any money, but to play a game until you reach a score &#8211; and it&#8217;s not a joke. <a href=\"https:\/\/t.co\/Pu53WZFALA\">pic.twitter.com\/Pu53WZFALA<\/a><\/p>\n<p>The ransom demand on the lock screen stated:<\/p>\n<p>Minamitsu \u201cThe Captain\u201d Murasa encrypted your precious data like documents, musics, pictures, and some kinda project files. It can\u2019t be recovered without this application because they are encrypted with highly strong encryption algorithm, using random key.<\/p>\n<p>As for how the files can be recovered, the creator of Rensenware wrote: \u201cThat\u2019s easy. You just play TH12 ~ Undefined Fantastic Object and score over 0.2 billion in LUNATIC level. This application will detect TH12 process and score automatically. DO NOT TRY CHEATING OR TERMINATE THIS APPLICATION IF YOU DON\u2019T WANT TO BLOW UP THE ENCRYPTION KEY.\u201d<\/p>\n<p>The Malware Hunter Team, however, <a href=\"https:\/\/twitter.com\/malwrhunterteam\/status\/850226771303702528\" target=\"_blank\">noted<\/a> that victims could edit their scores without consequences.<\/p>\n<p>Anime is not my thing and I\u2019ve never played this game, but lunatic difficulty level is presumably like hard mode on steroids; there <a href=\"http:\/\/shmups.system11.org\/viewtopic.php?t=34763\" target=\"_blank\">are<\/a> <a href=\"https:\/\/www.shrinemaiden.org\/forum\/index.php?topic=163\" target=\"_blank\">scoreboards<\/a> showing that at least some people have managed it.<\/p>\n<p>The ransomware was created to <a href=\"https:\/\/twitter.com\/malwrhunterteam\/status\/850037472981655552\" target=\"_blank\">automatically check<\/a> memory to make sure a victim reached the required level and score and would then decrypt files; once the score was reached, it also provided a way to <a href=\"https:\/\/twitter.com\/malwrhunterteam\/status\/850040182443257857\" target=\"_blank\">manually decrypt<\/a>\u00a0files in case any were missed.<\/p>\n<p>A Korea-based undergraduate student, who goes by <a href=\"https:\/\/twitter.com\/0x00000Ff\/\" target=\"_blank\">Tvple Eraser<\/a> on Twitter, was the mastermind of Rensenware; he did so because he \u201cwas bored\u201d and it was meant to be a joke. He <a href=\"http:\/\/kotaku.com\/anime-malware-locks-your-files-unless-you-play-a-game-1794120750\" target=\"_blank\">told<\/a> Kotaku that he fell asleep after releasing his joke on GitHub; when he woke up, his malware had spread. \u201cHe\u2019s not sure how many were affected, but added that, in the programming process, he\u2019d accidentally infected himself. When asked whether he could score 0.2 billion himself, the creator said, \u2018Uh, oh\u2026. Nope\u2019.\u201d<\/p>\n<p>Tvple Eraser then wrote an <a href=\"https:\/\/github.com\/0x00000FF\/rensenware_force\/blob\/master\/Apology.resx\" target=\"_blank\">apology<\/a> and created a <a href=\"https:\/\/twitter.com\/malwrhunterteam\/status\/850239122950168576\" target=\"_blank\">tool<\/a> which is like a cheat engine for the game as it would write a score high enough to force decryption. He said he was \u201creally sorry\u201d for shocking and annoying people with Rensenware.<\/p>\n<p>He \u201cmade it for joke, and just laughing with people who like Touhou Project Series,\u201d and realized he should have removed the encryption\/decryption logic before distributing the source code. He took down the source code and provided the decryption tool for victims infected with Rensenware.<\/p>\n<p dir=\"ltr\" lang=\"en\">So, the creator of rensenWare created a tool which writes the values to memory which are needed for the decryption.<br \/>Also wrote an apology&#8230; <a href=\"https:\/\/t.co\/LrapKv5Dm3\">pic.twitter.com\/LrapKv5Dm3<\/a><\/p>\n<p>On Sunday, he then <a href=\"https:\/\/twitter.com\/0x00000Ff\/status\/851279326574133254\" target=\"_blank\">released<\/a> a <a href=\"https:\/\/github.com\/0x00000FF\/rensenware-protect\/releases\" target=\"_blank\">Rensenware protector<\/a> that is not meant for already-infected machines. He has promised to never again \u201cmake any malware or any similar thing.\u201d<\/p>\n<p>When Rensenware was released, it would crash if conditions were not just right such as if it detected an optical drive that couldn\u2019t be encrypted. If conditions were right, then a PC infected with it would require the victim to go download the game if they didn\u2019t have it and play until the specified level and score was reached. You can see the crash, see the game and see the decryption tool work in danooct1\u2019s video.<\/p>\n<p><iframe loading=\"lazy\"  src=\"https:\/\/www.youtube-nocookie.com\/embed\/35mNhYY3O3k?rel=0\" width=\"100%\" height=\"420\" frameborder=\"0\" ><\/iframe> <\/p>\n<p>Perhaps the most worrying aspect of Rensenware is that between the time it was released and then the source code was yanked, it got out there in the interwebs. It may, or may not, inspire a ransomware author to tweak it or otherwise innovate and make it deadlier.<\/p>\n<p><a href=\"http:\/\/www.computerworld.com\/article\/3187520\/security\/new-ransomware-demanded-high-score-on-anime-style-shooter-game-not-bitcoins.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/zapt0.staticworld.net\/images\/article\/2016\/04\/frustrated-computer-user-100657949-primary.idge.jpg\"\/><\/p>\n<p><strong>Credit to Author: Darlene Storm| Date: Mon, 10 Apr 2017 09:23:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Never underestimate what a person can come up with when he or she is bored as was recently highlighted by the accidental release of a ransomware that required victims to reach an astronomically high score on an anime-style shooter game instead of paying an outrageous ransom in bitcoins.<\/p>\n<p>The Malware Hunter Team was <a href=\"https:\/\/twitter.com\/malwrhunterteam\/status\/850031671244193792\" target=\"_blank\">surprised<\/a> to discover Rensenware; they said the ransomware did not ask \u201cfor any money, but to play a game until you reach a score \u2013 and it\u2019s not a joke.\u201d<\/p>\n<p>Victims who wanted their files decrypted were required to score over 200 million points in the \u201clunatic\u201d level of the game <a href=\"https:\/\/en.touhouwiki.net\/wiki\/Undefined_Fantastic_Object\" target=\"_blank\"><em>TH12 ~ Undefined Fantastic Object<\/em><\/a>.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3187520\/security\/new-ransomware-demanded-high-score-on-anime-style-shooter-game-not-bitcoins.html#jump\">To read this article in full or to leave a comment, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[11070,11073,714],"class_list":["post-7299","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-emerging-technology","tag-malware-vulnerabilities","tag-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7299","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7299"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7299\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7299"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7299"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}