• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Princess Locker Reappears in the Form of Princess Evolution Ransomware

September 12, 2018Simeon Georgiev

Remember the Princess Locker Ransomware? Well, unfortunately, ransomware removal analysts have discovered its variant that has been referred to as Princess Evolution Ransomware. Similar to the Princess Locker Ransomware, this ransomware is also RaaS (Ransomware as a Service).

RaaS are paid services that are available on cybercriminal forums like dark net where dangerous third parties pay owners for their ransomware toolkit. The purchasing party then uses the ransomware to terrorize and exploit victims through ransomware attacks.

Analysis of the Ransomware

Ransomware removal analysts have expressed their worries regarding the flourishing ransomware industry, and the arrival of Princess Evolution Ransomware serves as an added dilemma for the security officials. Analysts believe that the actual owners are raking up 40 percent of the ransom payments while 60 percent goes into the pockets of the purchasing parties.  

According to ransomware removal analysts, the ransomware is spread through a number of different distribution strategies and channels. One of them has been identified as the RIG Exploit Kit. These kits are deployed and added on a large number of websites on the internet. The targeted websites are usually those that have high internet traffic where an event caused by the visitors means that the ransomware can make them cyber hostages.

Afterward, the ransomware will check two conditions. These conditions will help the ransomware to ensure that it has not targeted a victim twice. In case the ransomware enters into a previous victim’s PC, it will terminate its operation.

In the scenario of a new victim, Princess Evolution will begin its operation through communication with the CnC server via UDP. The information that will be provided to the CnC consists of the name of the victim, network interface details, OS type and versions and most importantly, the encryption key.

Ransomware removal experts have stated that so far the decryption tools for Princess Evolution have not been released, and hence it would be better to contact a professional service for ransomware removal.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post BlackBerry on a Crusade against Ransomware Next post Microsoft Employee Sentenced for Involvement with the Reveton Ransomware

Related Articles

Experts Discover a Variant of Cryptomix Ransomware

February 20, 2018Simeon Georgiev

Have a Machine Infected by Ransomware? Here’s What You Should Do

February 28, 2018Simeon Georgiev
Have a Machine Infected by Ransomware?

EITest HoeflerText potential Scam Spreading Netsupport Manager and GandCrab

March 1, 2018Simeon Georgiev
EITest HoeflerText potential Scam Spreading Netsupport Manager and GandCrab

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.