Ransomware attacks continue to pose a significant threat to both individuals and organizations. One such threat, LCRYX ransomware, written in VBScript, has recently resurfaced. First emerging in November 2024, it demanded a ransom of $500 in bitcoins to decrypt files encrypted with the ‘.lcryx’ extension. The ransomware has made a return in February 2025. A peer and researcher recently shared insights about this ransomware on their LinkedIn Profile. In this blog, we will conduct an in-depth analysis of the VB script, providing more details on its latest activity.
data:image/s3,"s3://crabby-images/6e0c9/6e0c9ace007331fe3040103f21b6752a259c37c9" alt=""
The script begins by checking whether it is running with administrative privileges. If not, it relaunches itself with the necessary privileges for the next steps. Additionally, error handling is enabled at the start of execution, allowing the script to continue running even if it encounters errors during its process.
data:image/s3,"s3://crabby-images/4e776/4e77678a28b1e7c4c656449a855df93cd709fe7c" alt=""
It then proceeds to make several changes to the Windows registry so as to block user control and for its persistence. It disables tools like Task Manager, Command Prompt, and the Registry Editor, and also blocks access to the Control Panel. The code turns off User Account Control (UAC) and admin prompts, letting the malware run with elevated privileges. It also disables the inactivity timeout, ensuring the system stays open for further actions.
data:image/s3,"s3://crabby-images/10668/10668f5fe70bb57149df7d1f239f5fa85acf9210" alt=""
data:image/s3,"s3://crabby-images/be935/be9350f862fa920dc44c2b009af1675ff90f65d9" alt=""
It also prevents users from running tools like msconfig.exe, Autoruns.exe, gpedit.msc, SystemSettings.exe, and procexp.exe, making it harder to manage start up items or stop the malware from executing.
data:image/s3,"s3://crabby-images/b3bae/b3bae1c312b3d22da7f61169b4253f0bdbee3482" alt=""
To ensure persistence, the code sets the malicious script as the default shell, causing it to run at login, and also configures it as the debugger for cmd.exe, making sure the script executes every time command prompt is opened. Additionally, it modifies the registry to set the script as the handler for HTTP and HTTPS links, ensuring that the script runs whenever web links are clicked or the system shell is accessed, allowing the malware to maintain control over the system.
data:image/s3,"s3://crabby-images/b8924/b8924af07df45da305dddc2a1af6c5f058725f61" alt=""
The code uses WMI to terminate key system processes (Taskmgr.exe, cmd.exe, msconfig.exe, regedit.exe) to prevent users from managing or stopping the malware.
data:image/s3,"s3://crabby-images/85939/8593906d39e384140f4f2cd1ef2c38735ddcd6bc" alt=""
It modifies the registry to remap keyboard keys and swap mouse buttons, disrupting user input. It applies these changes immediately, making it harder for users to interact with the system and helping the malware maintain control.
data:image/s3,"s3://crabby-images/43146/431467c547d234f54995e97dbcbd3880f3832793" alt=""
It changes the file attributes to Hidden, System, and Read-only, making it harder to detect, modify, or delete the file.
data:image/s3,"s3://crabby-images/4d378/4d378fd8c7ebfc5d322bd1172e0e1d7f10a9b2fb" alt=""
It runs a PowerShell command that reads an image file and overwrites the MBR of disk drives with its content.
data:image/s3,"s3://crabby-images/354d8/354d8738bd5911822c1ac51f560453bfddc4127f" alt=""
The code disables real-time monitoring of Windows Defender, Bitdefender Antivirus, and Kaspersky Anti-Virus by running commands to turn off their protection features. This allows malware to bypass security measures and operate undetected on the system.
data:image/s3,"s3://crabby-images/e1e9c/e1e9c0a4458b893c8e562d4a6c32808371177cea" alt=""
data:image/s3,"s3://crabby-images/f163c/f163c12cccc86a5fa24fb212fb46a751d22e7700" alt=""
It defines a function IsLegacyWindows() to check if the system is running an older Windows version (prior to version 6.0). If so, it retrieves various special folder paths for potential file manipulation or malware persistence.
data:image/s3,"s3://crabby-images/733e4/733e41473b02676ed8140cdf3bf0f119f5b7dc0c" alt=""
The GenerateRandomKey(length) function creates a random alphanumeric string by selecting characters from a predefined set. It loops through the specified length, adding a random character to the key in each iteration, which was later used as key for the encryption process.
data:image/s3,"s3://crabby-images/328c0/328c07fb4f269604924df6e0ef80258e62563812" alt=""
The code checks if the file path matches certain conditions, like specific filenames. If it does, the script stops. Otherwise, it encrypts the file using Caesar cipher and XOR encryption, saves it with a new extension, deletes the original file, and opens the encrypted file in Notepad.
data:image/s3,"s3://crabby-images/36b21/36b21e39cfbadfb7bf545e12e27aa0eba9b07e8c" alt=""
data:image/s3,"s3://crabby-images/812e3/812e396906fcd39123e305b9f1dae16098ec5de1" alt=""
data:image/s3,"s3://crabby-images/1e7ed/1e7edf7c423f1f15e74f89aee6941a970b6de6a2" alt=""
data:image/s3,"s3://crabby-images/6b983/6b98318c43fffd2fd2ffc73bab0c4e660dbf444e" alt=""
data:image/s3,"s3://crabby-images/ecff0/ecff0925bad8345bcd906844ee548a0651e5c59a" alt=""
It iterates through these following folders in the system and it checks for any external drivers in its iteration for encrypting the files.
data:image/s3,"s3://crabby-images/18170/181709164cf99f549bee7be14c5deb40e7cb8a45" alt=""
data:image/s3,"s3://crabby-images/ce646/ce6461ede8f91f91e242d16741404ad4a32b61f0" alt=""
After that it deletes backup files with specific extensions (.bak, .backup, .old) from a folder and its subfolders, and another that removes shadow copies and backup catalogs. It uses vssadmin to delete shadow copies and wbadmin to clear the backup catalog, effectively erasing backup traces from the system.
data:image/s3,"s3://crabby-images/abbda/abbda5ee4e54373d96db0a769f8f39ca07af8749" alt=""
data:image/s3,"s3://crabby-images/899b8/899b87772d0460ca2847fdfc3fbdaa879dd5cc3d" alt=""
Then it generates a ransom note on the desktop, in which it asks the user to visit a website and pay a ransom in bitcoin for file decryption.
data:image/s3,"s3://crabby-images/8f249/8f249a47afb0e26a2c831a985e52fabb9124eaa3" alt=""
This VBScript automatically downloads an image from a provided URL and sets it as the desktop wallpaper, but only if an internet connection is detected. It includes checks for connectivity, downloading the file to the desktop, and updating the wallpaper registry setting. The script also handles errors and alerts the user if something goes wrong.
data:image/s3,"s3://crabby-images/d8bb1/d8bb1b9d3a27123c46e4d4cc8b0c8346cb45b9cf" alt=""
data:image/s3,"s3://crabby-images/e75ab/e75ab2b741bc3798fc45d87fce3581abc93eb2de" alt=""
Then it creates three files: one batch file and two VBScript files. It then adds content to these files and creates persistence by adding registry entries to ensure these files are executed on system start up, allowing for further actions upon their execution.
data:image/s3,"s3://crabby-images/89ec4/89ec47a51449e588c1c52bb6f55584803ad9e57f" alt=""
Then it adds content to the batch file that runs in a loop three times. In some variants each time, it opens the calculator (calc) and command prompt (cmd) while in some other variants it makes connections to some malicious urls which are shown in Fig.28. The script sets up the loop and commands to execute repeatedly, with no output shown during execution. Then it creates persistence for the batch file and in some variants, it also creates random directories and keeps this batch file in those randomly generated folders.
data:image/s3,"s3://crabby-images/92cf4/92cf4c25d13eb3c562616b8ea06a176a2026c61b" alt=""
data:image/s3,"s3://crabby-images/ecc69/ecc6922871143288d25961123d78c0cc7fc79c59" alt=""
data:image/s3,"s3://crabby-images/a0349/a034998c4f30415b4d27ce52e238bc4d8075d0c0" alt=""
Then it creates a VBScript which runs in a loop, for displaying a message claiming that files have been encrypted. It asks the user if they want to decrypt their files. If the user clicks “Yes,” it runs a command, opens a YouTube video, and shows the user’s IP address. The script keeps repeating the process. It also creates the persistence by making changes in the registry entries for this VBScript file.
data:image/s3,"s3://crabby-images/015f3/015f33081869f12cfb7447d06aef9905d5896367" alt=""
data:image/s3,"s3://crabby-images/379fa/379fa9d2e45c3ea31d212ab8af02d624ad396a66" alt=""
In another, VBScript it repeatedly shuts down important programs like Task Manager, PowerShell, and AntiVirus software. It uses the taskkill command to close these programs every 5 seconds in a never-ending loop. The script targets tools like AntiVirus programs and system settings, making it potentially harmful. For this VBScript file also it creates the persistence by making changes in the registry entries.
data:image/s3,"s3://crabby-images/43111/43111db3af114de270f7c26642931ca7ca38153f" alt=""
Then it runs these newly created files with these commands as shown in Fig.33.
data:image/s3,"s3://crabby-images/7b22f/7b22fa4e43262b3e6af30882d2c6b953d7ef4f23" alt=""
data:image/s3,"s3://crabby-images/45c1a/45c1a0c976572835a5a1120e9a4df3146a06e6a6" alt=""
With the increasing risk of ransomware attacks, it’s important to take steps to protect your data. Using a reliable security solution like K7 Total Security and keeping it updated is crucial to defend against these threats.
IOCs
Hash | Detection Name |
57D4D27F915A6352918C878450582F44 | Trojan ( 0001140e1 ) |
5999A77CF9015AF51938E162584A37BC | Trojan ( 0001140e1 ) |