According to the analysis of Kaspersky Lab, the hashing algorithm used in the “Bad Rabbit” attack is similar to the one used in “ExPetr”.
Furthermore, experts found that both attacks use the same domains and similarities in the respective source codes indicate that the new attack is linked to the creators of "ExPetr.".
Like "ExPetr," "Bad Rabbit" attempts to extract login credentials from system memory and spread across the corporate network via WMIC. However, researchers did not detect either the EternalBlue or EternalRomance exploits in the "Bad Rabbit" attack. Both were used in "ExPetr.".
The investigation shows that the attackers behind this operation had been preparing for it since at least July 2017, creating their "infection" network on compromised websites, which are mainly media and news sources.
According to Kaspersky Lab research, “Bad Rabbit” hit nearly 200 targets located in Russia, Ukraine, Turkey and Germany. All attacks took place on October 24, and no new attacks have been detected since then. The researchers note that once the “infection” became more widespread and security companies began investigating, the attackers immediately dropped the malicious code they had added to the compromised websites.
Vyacheslav Zakorzhevsky, Head of the Anti-Malware Research Team at Kaspersky Lab, commented: “According to our data, most of the victims of these attacks are located in Russia. This ransomware “infects” devices via some compromised Russian media websites. Based on our research, this was a targeted attack against corporate networks, using methods similar to those used during the “ ExPetr ” attack .
Kaspersky Lab products detect the attack with the following resolutions: UDS : DangerousObject . Multi . Generic (detected by Kaspersky Security Network ), PDM : Trojan . Win 32. Generic (detected by System Watcher ), and Trojan – Ransom . Win 32. Gen. ftl .
We recommend that our corporate customers ensure that all protection mechanisms are enabled as recommended, and that KSN and System Watcher features (which are enabled by default) are not disabled. For companies that do not use security solutions, we recommend that they restrict the execution of files with the paths c :\ windows / infpub . dat and C :\ Windows \ cscc . dat using System Administrator tools.”
In the video below you can see the Bad Rabbit ransomware in action and how Kaspersky Lab security solutions successfully detect and block the data encryption attempt.
