The GandCrab ransomware, which has created a stir in the cybersecurity industry with its continuous evolution, has caused a stir again. The latest version of the ransomware uses an SMB exploit spreader via exposed websites. The ransomware is adding new features every day to target different countries.
The attackers behind the ransomware are scanning the entire internet for vulnerable websites to launch the attack. The latest version includes a long hard-coded list of vulnerable websites that were used to carry out the attack.
A pseudo-random algorithm has been used by the attackers to select a predefined word to fill in the URL for each host, and the final URL is created in the format “www. Host”.com/data/tmp/sokakeme.jpg”.
According to several reports, this newer version of the ransomware can be spread via an “SMB exploit.” Interestingly, the same exploit was used to spread the WannaCry and Petya/NotPeta ransomware attacks last year.
To spread via SMB vulnerabilities, the entire ransomware code was rewritten and the malware now uses EternalBlue National Security Agency (NSA) exploits to attack more quickly.
A study suggests that a module named “network f**ker” is responsible for SMB exploits.
Fortinet, an internet security company, said that “with the rapid growth of GandCrab over the past week and the public speculation of this exploit, it would not be surprising if the attackers behind it decided to add it in a future update.”
However, Microsoft has turned its attention to ransomware and has released a security patch MS17-010. To protect your system, make sure it is up to date with the latest security patch.
