Cybercriminals Unveil Doubleface Ransomware, Promising Complete Stealth

A newly unveiled ransomware variant known as Doubleface has been revealed by its developers. This latest malware claims to offer advanced features and asserts that it is entirely invisible to leading antivirus solutions.

In a recent tweet by Dark Web Informer, the launch of Doubleface Ransomware was announced with the bold claim of complete undetectability.
🚨Introducing Doubleface Ransomwarehttps://t.co/zQLMGPg5rt

The tweet includes the following message:

Hello Doubleface Enthusiasts and Followers,

The Doubleface Ransomware is now available and ready for deployment.

This ransomware comes equipped with a… pic.twitter.com/QZcPUILsEL
— Dark Web Informer (@DarkWebInformer) August 5, 2024

Developed with a proprietary encryption algorithm, Doubleface ransomware utilizes both AES-128 and RSA-4096 encryption. Each file is encrypted with a randomly generated AES key, which is then encrypted using RSA, creating a dual-layer encryption system that is purportedly very difficult to break without the specific RSA decryption key.

Built with C/C++ programming languages, known for their high efficiency and performance, Doubleface’s creators have also released a video showcasing its operation, providing insight into its functionality and claims.

Claims of Complete Undetectability

A particularly concerning claim by the Doubleface team is its assertion of being fully undetectable. The ransomware has been tested against major antivirus solutions including Windows 10/11 Defender, Avast, Kaspersky, and AVG, and reportedly managed to avoid detection by all.

This undetectable nature represents a serious threat, as it may circumvent existing cybersecurity defenses in many organizations.

Doubleface features sophisticated defensive mechanisms, including Anti-Virtual Machine, Anti-Debugging, and Anti-Sandbox techniques, which make it increasingly difficult for security professionals to analyze and counteract.

Cost and Access

Doubleface ransomware is priced at $500 per instance, while the source code, which is also undetectable, is available for an eye-watering $10,000.

The developers have highlighted that no separate stub is needed for decryption, but users must keep track of each stub’s key carefully. A critical caution is issued: attempting to decrypt files with an incorrect key will result in the complete destruction of all files.

This revelation has generated considerable alarm within the cybersecurity sector, underscoring the evolving and increasingly sophisticated tactics employed by cybercriminals. The necessity for vigilant and adaptive cybersecurity measures has never been clearer as organizations prepare for potential breaches.

More Articles & Posts