A massive ransomware operation , dubbed “ Operation Kofer, ” has emerged in cyberspace —one that has the ability to mutate to fool detection mechanisms.
Cybereason Labs researchers , after examining various variants of Kofer ransomware from around the world, discovered that they share the same construction and delivery techniques but also incorporate random variables to evade static-signature and hash-based detection.
This led the research team to believe that all the variants were created by the same hacker group who used a specific algorithm to mix and match the components differently, thus giving the ransomware evasion capabilities similar to APTs.
The Kofer samples analyzed by experts had different hashes and characteristics, but the same traits and properties, such as fake icons , fake file names, and a specific packaging pattern, which connects the samples, which would otherwise seem unrelated, under a single operation.
In addition to mechanisms that help avoid detection by sandboxes and dynamic detection tools, Kofer variants also include decorative elements aimed at misleading researchers.
"The fact that Kofer variants come from only one source is an example of the commercialization of ransomware on a whole new level," says Uri Sternfeld, of Cybereason.
“Operation Kofer appears to be the first drive-by ransomware operation to incorporate an APT/nation-state level of sophistication, making its product an increasingly significant threat to organizations.
Regarding the uncontrolled proliferation of variants, all of them were found and compared in the past weeks, while new ones are probably being created every few days or even hours!
Cybereason believes that Operation Kofer already has a pan-European presence, as confirmed by researchers who have identified versions in Spain, Poland, Switzerland, Turkey, and others .
