RanRan ransomware virus targets Middle Eastern governmental organizations
RanRan ransomware is a unique file-encrypting virus that held few attacks against government organizations in the Middle East.[1] The virus has political connotations[2] and does not behave like ordinary ransomware. It’s already known that it attacked Saudi Arabia, more specifically – country’s leader King Salman bin Abdulaziz Al Saud. However, it seems that the same virus held another attack in the Philippines in January 2017.[3] The ransom note delivered by the RanRan virus asks Middle Easter government organizations, or victims, to make political statement against the leader of the country by creating a particular public sub-domain. It’s uncommon behavior for the ransomware because cyber criminals do not directly demand to pay the ransom like their counterparts. The instructions what criminals have to do are explained in the zXz.html file (the full message is presented below). After following the orders, victims just have to wait for the hackers’ response. Nevertheless, it’s unusual example of the file-encrypting virus; it’s better to remove RanRan from the system than dealing with cyber criminals.
!!!Congratulations!!!
Welcome to my Ransomware!
Cannot you find the fies youneed?
is the content of the files that you have watched not readable?
I want to play a game with you. Let me explain the rules:
Your documents, photos, databases and other important files have been encrypted
with strongest encryption and unique key generated for this computer.
Private decryption key is stored on a secret internet server and nobody can decrypt
your files until you pay and obtain the private key.
But, don’t worry!
It is normal because the file, names as well the data in your files have been encrypted.Do no: power off compuer, run antivirus program ,disable internet connection. Failures during key recovery
and file decryption may lead to accidental damage on files.In order to have relationship with us, and pay the ransom; must go the following steps:
1. Launch a subdomain named:
XXXXXXXXXXXXXXXXXXXXXXXXXXXX
2. Make atxt file named:
ransomware.txt including:
Hacked!
“Your email address”
We will text you ASAP.
Malware researchers haven’t found RanRan distribution methods yet. However, when a victim runs an infected computer, the virus immediately starts looking for a mutex[4]. If it finds it, the virus understands that the computer is already infected and stops the execution process. It roots into the system by creating autorun key using an encoded base64 string which creates a new registry key. Then, the virus locates itself to the “C:\services.exe” file. RanRan ransomware also shuts down various processes that are mostly related to database servers. To prevent them from starting and running, the virus monitors them regularly and closes if necessary. Then, the virus starts scanning the system looking for the targeted files. It aims at the Microsoft Office files, various image, audio, video and other often used files. Though, the encryption procedure quite differs from the regular ransomware viruses, because it might use two encryption methods. If the virus finds a Supplied Rsa Public Key located in the“C:\pubkey”, it uses it for the data encryption. Otherwise, it employs Built-in MD5 Hash Encryption. This mechanism uses a randomly generated md5 hash of string which is written to the “C:\WINDOWS\pass.” This string is used as an RC4 password which is generated for the particular groups of files. Before starting data encryption, RanRan virus categorizes files by the size into 8 groups. For each cluster it generates unique passwords. Then, the virus encodes each of the used keys with RSA public key, and renames files using this pattern: VictemKey_[lower_bound]_[upper_bound] and appends .zXz file extension. Below you can find the list how virus categorizes the files and renames them during the encryption:
File size: 0 – 5 MB -> example of the file name after encryption: VictemKey_0_5.zXz
File size: 5 – 30 MB -> example of the file name after encryption: VictemKey_5_30.zXz
File size: 30 – 100 MB -> example of the file name after encryption: VictemKey_30_100.zXz
File size: 100 – 300 MB -> example of the file name after encryption: VictemKey_100_300.zXz
File size: 300 – 700 MB -> example of the file name after encryption: VictemKey_300_700.zXz
File size: 700 – 2000 MB -> example of the file name after encryption: VictemKey_700_2000.zXz
File size: 2000 – 3000 MB -> example of the file name after encryption: VictemKey_2000_3000.zXz
File size: 3000 MB and greater -> example of the file name after encryption: VictemKey_3000.zXz
Nevertheless, RanRan ransomware for data encryption uses complex methods; malware researchers found out that there’res several mistakes in this procedure. For instance, during encryption, some files are not deleted but encrypted only. Researchers from Paulo Alto Network discovered how victims could decrypt their files[5]. However, before starting data encryption procedure, victims have to perform the RanRan removal. We suggest employing FortectIntego or MalwarebytesMalwarebytes to wipe out malware from the system.

How does ransomware spread?
We have already mentioned that it’s unknown how RanRan malware spreads. Though, it might be using one of the widely used distribution methods: malicious spam emails and their attachments, malvertising, exploit kits, bogus software updates, and downloads, etc. Thus, in order to avoid ransomware, computer users are advised to be careful with email attachments and do not rush opening them, avoid clicking suspicious or eye-catchy ads and stay away from insecure sources for downloads. To minimize the risk of ransomware attack helps installed a professional antivirus program. However, you should not forget to update security tools and other programs installed on the PC.
How to remove RanRan ransomware virus?
For RanRan removal we recommend employing reputable malware removal tools such as FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Manual virus elimination is not recommended because malware-related components might be rooted in the system and they might be hard to find. What is more, some of the malicious files might be obfuscated and look like legitimate system files. Thus, it’s better to leave this task for professional tools and do not risk causing more damage to the computer. Ransomware might prevent from installing, updating or accessing security programs. If you cannot run your chosen software and remove RanRan automatically, reboot your computer to the Safe Mode and try again. You will find explanations below.
Did this guide help?
3 comments
tornado
Political-themed viruses are quite interesting. I know it may sound horrible, but I am curios what developers of the RanRan are planning to do next.
Marta
This ransomware is interesting.
Federica
Its brave to attack the leader of Saudi Arabia...