FYI: There’s another BlackCat ransomware variant on the prowl

Here’s a heads up. Another version of BlackCat ransomware has been spotted extorting victims. This variant embeds two tools, we’re told: the network toolkit Impacket for lateral movement within compromised environments, and Remcom for remote code execution.

BlackCat, also known as AlphaV, is a notorious ransomware crew whose affiliates lately have taken to compromising hospitals and medical clinics, stealing medical records, and demanding a ransom to keep that information under wraps. Many of these healthcare orgs would rather pay up than face lawsuits from patients when their protected files are leaked or sold online by the extortionists over non-payment.

The BlackCat malware works on Windows and Linux, and is rented out to criminals, who break into targets and run the data-stealing malware, making it a ransomware-as-a-service operation. Under this business model, the affiliates pay to use the malware developed by operators in their attacks, and then the affiliates earn a cut of the proceeds if the victims pay the ransoms.  

For BlackCat affiliates, that reportedly translates to between 80 and 90 percent of the amount paid, we’re told.

This particular extortion operation was first seen in the criminal underground in 2021, and it was noteworthy because it was one of the first ransomware strains to be written in Rust. Since then, it’s been updated, with operators adding features and improvements.

And in a series of social media posts on Thursday, the Microsoft Threat Intelligence team said they spotted a new version being used by a BlackCat affiliate in July.

It seems the version Redmond has analyzed is the Sphynx version of BlackCat ransomware that the eggheads at IBM Security X-Force and VX-Underground have been warning about since the spring.

VX-U is confident the BlackCat strain it flagged up in April is the same one the Azure titan is now talking about.

Impacket + Remcom

The new version, according to Microsoft, uses Impacket, a freely available collection of Python code for working with network protocols.

This tool allows miscreants to move laterally across the network, and “has credential dumping and remote service execution modules that could be used for broad deployment of the BlackCat ransomware in target environments,” the Windows giant said.

Additionally, this BlackCat version also has Remcom, which allows attackers to execute code and copy files on remote systems, embedded in the executable, we’re told.

“The file also contains hardcoded compromised target credentials that actors use for lateral movement and further ransomware deployment.”

While Microsoft doesn’t say what July intrusions used this new version of BlackCat, one of the gang’s affiliates did break into Barts Health NHS Trust, one of the UK’s largest hospital groups, that month.

That infection followed one in June at California’s Beverly Hills Plastic Surgery, during which crooks claimed to steal personal information and healthcare records, “including a lot of pictures of patients that they woud [sic] not want out there.” ®

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Mega-Popular Muslim Prayer Apps Were Secretly Harvesting Phone Numbers thumbnail

Mega-Popular Muslim Prayer Apps Were Secretly Harvesting Phone Numbers

Photo: Pavlo Gonchar/SOPA Images/LightRocket (Getty Images)Google recently booted over a dozen apps from its Play Store—among them Muslim prayer apps with 10 million-plus downloads, a barcode scanner, and a clock—after researchers discovered secret data-harvesting code hidden within them. Creepier still, the clandestine code was engineered by a company linked to a Virginia defense contractor, which…
Read More
Wasserstoff, No Man's Sky, MCM: Intel arbeitet an GPU-Chiplets thumbnail

Wasserstoff, No Man’s Sky, MCM: Intel arbeitet an GPU-Chiplets

Cookies zustimmen Besuchen Sie Golem.de wie gewohnt mit Werbung und Tracking, indem Sie der Nutzung aller Cookies zustimmen. Details zum Tracking finden Sie im Privacy Center. Skript wurde nicht geladen. Informationen zur Problembehandlung finden Sie hier. Um der Nutzung von Golem.de mit Cookies zustimmen zu können, müssen Cookies in Ihrem Browser aktiviert sein. Weitere Informationen…
Read More
Simona Halep, brilliant reaction about Emma Răducanu's appearance in Romania.  Everyone laughed when they heard it thumbnail

Simona Halep, brilliant reaction about Emma Răducanu's appearance in Romania. Everyone laughed when they heard it

Simona Halep a venit cu o reacție aparte despre apariția Emmei Răducanu în România. Ce a spus jucătoarea de tenis? Toată lumea a râs când i-a auzit reacția. Simona Halep, despre venirea Emmei Răducanu în România: reacția sportivei Emma Răducanu este surpriza de anul acesta în tenis. Aceasta a câștigat celebrul turneu american US Open,…
Read More
Catch up on Linux.conf.au 2014 thumbnail

Catch up on Linux.conf.au 2014

If you failed to make the trip to Perth for LCA this year, you are able to watch most of the talks online. Linux.conf.au took place last week in Perth, and this year, the conference's video team has outdone itself, with the session videos appearing the next day in a lot of cases. The videos…
Read More
The TicWatch Pro 3 Ultra, GTH+ and GTH Pro feature advanced heart rate monitoring. thumbnail

The TicWatch Pro 3 Ultra, GTH+ and GTH Pro feature advanced heart rate monitoring.

มีรายงานออกมาว่าสมาร์ทวอทช์รุ่นใหม่ของทาง Mobvoi อย่างรุ่น TicWatch Pro 3 Ultra, GTH+ และ GTH Pro จะมาพร้อมฟีเจอร์สำหรับตรวจวัดอัตราการเต้นของหัวใจขั้นสูงMobvoi ได้ประกาศ TicWatch GTH ไปเมื่อต้นปีที่ผ่านมา โดยสมาร์ทวอทช์รุ่นนี้มาพร้อมฟีเจอร์สำหรับตรวจวัดอุณหภูมิของผิว ควบคู่ไปกับฟีเจอร์ด้านสุขภาพอื่น ๆ ด้วยรายงานล่าสุดเผยว่า Mobvoi กำลังเตรียมเปิดตัวสมาร์ทวอทช์รุ่นใหม่อย่าง TicWatch Pro 3 Ultra, GTH+ และ GTH Pro ที่มีข่าวลือว่าสมาร์ทวอทช์จะมาพร้อมฟีเจอร์ตรวจวัดอัตราการเต้นของหัวใจขั้นสูง โดยข้อมูลนี้ถูกค้นพบในการแกะแอป APK เวอร์ชัน 4.3.0 ของทาง XDA Developersตามข้อมูลดูเหมือนว่าตัวฟีเจอร์นั้นจะมีความสามารถที่หลากหลาย ไม่ว่าจะเป็นการตรวจอายุทางชีวภาพของหัวใจ (Arterial Age), ความสามารถของหัวใจในการให้เลือดพร้อมออกซิเจนไปยังเซลล์ตามที่ร่างกายต้องการ (Exercise Capacity), ภาระในหัวใจจากการแข็งตัวของหลอดเลือดแดง (HSX) และวิธีการวัดอัตราการเต้นของหัวใจที่มีความแม่นยำเท่ากับวิธีการแบบ ECG มาตรฐาน (TruHR)ดูเหมือนว่าฟีเจอร์เหล่านี้จะได้รับความร่วมมือจากทาง AtCor Medical Inc บริษัทด้านการแพทย์ของออสเตรเลียซึ่งเป็นบริษัทในเครือของ CardieX…
Read More
Index Of News
Total
0
Share