November 16, 2016

A security researcher named slipstream/RoL has discovered the Karma Ransomware, which pretends to be a Windows optimization program called Windows-TuneUp. What is worse is that this sample was discovered as software that would potentially be distributed by a pay-per-install software monetization company when people install free software downloaded from the Internet.

I have been railing against adware and PUA purveyors for quite some time and this continues to show how dangerous bundled software is becoming.
encrypt ransomwareIf a user downloads and installs a free program that is monetized by this software monetization company, they would possibly be greeted with an offer for a Windows optimization program called Windows-TuneUp. While many people know these types of programs are not ones you want on your computer, there are unfortunately many who do not realize this. These people would then accept the offer thinking they are getting a program that will help optimize their slow computer.

When the program runs, they will be presented with a screen that shows various performance stats and tools to supposedly increase the performance of their computer.
Also, if they had gone to the program’s web site they would have been shown a web page that appears to look like a legitimate software company.

windows tuneup page                                                                   Windows-TuneUp Web Site

Unfortunately, this is just a ruse and while the victim’s are playing with the fake program or reading the website, the program is silently encrypting the data on the computer and its connected drives.  It is not until they are shown the Karma Ransomware’s ransom note do they realize that they have been tricked and that their computer has a serious problem.

ransom note                                                                         Karma Ransomware Ransom Note

The good news is that this ransomware was very short-lived and the Command & Control server has already been shut down. Therefore, even if this ransomware is still being distributed, victims will not become infected.

It does, though, provide a very important lesson, which is anyone who downloads free software over the Internet should decline any offers that may be presented. In my experience, any offers being presented by free downloads are just not worth the headache they may present and should simply be avoided. Try instead to only download programs that are are adware and PUP free.

When it encounters one of the above file types it would encrypt it using AES encryption and append the .karma extension to the filename. For example, test.jpg would become test.jpg.karma. While encrypting files, it would skip all folders that contain the following strings:
Finally, when it was done encrypting the files it will create ransom notes on the Desktop called # DECRYPT MY FILES #.html and # DECRYPT MY FILES #.txt and display them.

Last, but not least, it will create a Scheduled Task which will automatically start Windows-TuneUp.exe after it has been closed. This schedule task is called pchelper.

karma ransomwareIOCS:
