HomeSecurityGreek companies victims of CrySIS/Dharma ransomware! An attack without end?

Greek companies victims of CrySIS/Dharma ransomware! An attack without end?

According to several reports from small and medium-sized businesses and giants in Greece, in 2019 the CrySIS or Dharma ransomware, which has been terrorizing its victims since 2016, has infected several companies.

CrySIS

While the global online community believed that the tyranny of CrySIS ransomware had passed, several Greek businesses are proving this wrong by falling victim to the malware and paying - most of them - large sums of money to decrypt their files.

In fact, according to Malwarebytes Labs, you are seeing a 148% increase in CrySIS ransomware attacks from February to March 2019, globally.

In the Greek business world, ransomware seems to have alarmed several companies that considered themselves invulnerable or that never expected to become a target of hackers.

According to an investigation by SecNews , the hackers behind the attacks are clearly aiming to collect the ransom money they are demanding . This means that the companies are not being targeted by personal interests or conspiracies by their competitors.

The hackers act as "professionals" and once they receive the ransom, they send the key to decrypt the files.

According to SecNews' research, Chinese and/or Russian hacking groups. In fact, these are organized groups that have earned millions (!) of dollars [ed. $500,000,000] from malicious actions.

CrySIS Greek companies

What is CrySIS/Dharma ransomware and how does it work?

CrySIS/Dharma targets Windows systems, and is primarily aimed at businesses. It uses several distribution methods:

  • CrySIS is distributed as malicious attachments in spam emails. Specifically, the malicious attachments use duplicate file extensions, which within default Windows settings may appear to be non-executable, when in fact they are.
  • CrySIS can also end up masquerading as installer files for legitimate software, including AV vendors. The hackers behind CrySIS offer the “harmless” installers for various legitimate applications as downloadable executable files, which have been distributed via various locations on the Internet and on shared networks.
  • Most often, CrySIS/Dharma is delivered manually in targeted attacks, exploiting RDP leaked or weak forcing the Windows RDP protocol on port 3389.

In a recent attack, CrySIS was sent as a download link in a spam email. The link redirects to a password. The password was given to potential victims in the email and in addition to the CrySIS/Dharma executable, the installer contained an outdated removal tool from a well-known security vendor.

This social engineering strategy was used to avoid raising suspicions among users. Seeing a familiar security solution in the installation package, they assumed the downloadable was safe.

CrySIS ransomware Greek companies

The infection

Once CrySIS infects a system, it creates registry entries and encrypts almost every type of file, bypassing system and malware files. It performs encryption using a strong encryption algorithm (AES-256 combined with asymmetric RSA-1024 encryption), which is applied to fixed, removable, and network drives.

Before encryption, CrySIS deletes all Windows Restore Points by running the command vssadmin delete shadows /all /quiet.

The Trojan that spreads due to ransomware collects the computer name and the number of encrypted files from certain formats, sending them to a remote C2 server controlled by the hacker. On some Windows versions, it also tries to act with administrator privileges, thus expanding the list of files that can be encrypted.

After a successful RDP-based attack, it was observed that before executing the ransomware payload, CrySIS uninstalls the security software installed on the system.

ransomware Greek companies

The Ransom

When CrySIS completes the encryption, it leaves a note on the desktop stating how much the victim must pay if they wish to get their files back, providing two email addresses for contacting the hackers.

The ransom demanded is usually around 1 Bitcoin, but there have been cases where the pricing seems to be adjusted according to the revenue of the affected company. Financially healthy companies often pay a higher amount.

How to protect yourself?

While you have the option of using other software to remotely operate your work computers, RDP is essentially a secure and easy-to-use protocol with a pre-installed client on Windows systems, as well as clients available for other operating systems. There are a few steps you can take to make it much more difficult for someone to gain access to your network through unauthorized RDP:

  • To make it harder for a brute force attack to succeed, use strong passwords.
  • Do not disable Network Level Authentication ( NLA) as it provides an additional layer of authentication. Enable it if it is not already enabled.
  • Change the RDP port so that port-scanners looking for open RDP ports miss yours. By default, the server listens on port 3389 for both TCP and UDP.
  • Or use a remote Gateway Server, which also gives you some additional security and functionality benefits like 2FA. can logs RDP session be particularly useful when you want to track down various activities. Since these logs are not on the compromised machine, they are harder for hackers to tamper with.
  • Restrict access to specific IP addresses, if possible. There should be no need for multiple IPs needing RDP access.
  • There are many ways to escalate user privileges on Windows computers, even when using RDP, but all known methods have been patched. So, as always, make sure your systems are fully updated and patched.
  • Use an effective and easy-to-use backup strategy. Relying on Restore Points is not a good idea and is completely useless when ransomware deletes restore points first, as is the case with CrySIS.
  • Train your staff about phishing attacks and raise their awareness about cyber security.
  • Finally, use a multi-layered, advanced security solution to protect your machines from ransomware attacks.

Greek companies victims of CrySIS/Dharma ransomware! An attack without end?

IOCs

Ransom.Crysisis known to use these extensions for encrypted files:

.crysis, .dharma, wallet, .java, .adobe, .viper1, .write, .bip, .zzzzz, .viper2, .arrow, .gif, .xtbl, .onion, .bip, .cezar, .combo, .cesar, .cmb, .AUF, .arena, .brrr, .btc, .cobra, .gamma, .heets, .java, .monro, .USA, .bkp, .xwx, .btc, .best, .bgtx, .boost, .heets, .waifu, .qwe, .gamma, .ETH, .bet, ta, .air, .vanss, . 888, .FUNNY, .amber, .gdb, .frend, .like, .KARLS, .xxxxx, .aqva, .lock, .korea, .plomb, .tron, .NWA, .AUDIT, .com, .cccmn, .azero, .Bear, .bk666, .fire, .stun, .myjob, .ms13, .war, .carcn, .risk, .btix, .bkpx, .he, .ets, .santa, .gate, .bizer, .LOVE, .LDPR, .MERS, .bat, .qbix, .aa1, and .wal

 

So far, the following ransomware names have been identified:

  • txt
  • HOW TO DECRYPT YOUR DATA.txt
  • Readme to restore your files.txt
  • Decryption instructions.txt
  • FILES ENCRYPTED.txt
  • Files encrypted!!.txt
  • hta

Common file hashes:

  • 0aaad9fd6d9de6a189e89709e052f06b
  • bd3e58a09341d6f40bf9178940ef6603
  • 38dd369ddf045d1b9e1bfbb15a463d4c

 

ransomware

In case you have fallen victim to this specific attack, you can contact the SecNews research team by clicking on https://www.secnews.gr/ask-us/.

 

For confidentiality reasons, the names of the Greek companies that have fallen victim to CrySIS/Dharma ransomwareare not being disclosed.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS