
A new ransomware , recently discovered, targets Windows and Linux systems . The ransomware is called Tycoon and has been active since December 2019. Experts believe it is the work of criminals who are very selective in targeting their victims. The malware also uses an unusual technique that helps it remain hidden on compromised networks.
Most of Tycoon's victims are organizations in the education and software industries .
Tycoon was discovered and analyzed by researchers at BlackBerry and KPMG. It is an unusual form of ransomwarebecause it is written in Java, deployed as a trojanised Java Runtime Environment, and disguised as file Java image (Jimage) to hide its malicious intent.
These methods are not commonly used in ransomware. “Java is rarely used to create malware because it requires the Java Runtime Environment to be able to execute the code. Also, image files are rarely used for malware attacks,” said Eric Milam, a BlackBerry executive.
"Attackers are turning to unusual programming languages and 'weird' data formats. Here, the attackers did not have to hide their code, but they managed to achieve their goals," he added.

However, the first stage of Tycoon ransomware attacks is quite common. The initial intrusion is through unsecured RDP servers. This method is often used for attacks and exploits servers with weak or already compromised passwords.
Once inside the network, attackers use Image File Execution Options (IFEO) injection settings, which often provide developers with the ability to detect software bugs. Hackers also attempt to disable anti-malware software using ProcessHacker.
After execution, Tycoon ransomware encrypts the network. The encrypted files acquire extensions such as .redrum, .grinch, and .thanos. The attackers then demand a ransom from the victims to “free” the data. The attackers demand the ransom in bitcoins and claim that the price depends on how quickly the victim contacts them via email.
The fact that the campaign is still ongoing shows that the attacks are successful.
Researchers believe that Tycoon could potentially be linked to another form of ransomware, Dharma (also known as Crysis), as they share several similarities.
Although Tycoon uses some rare attack methods, we can prevent its execution.
Organizations should properly secure their RDP servers and ensure that accounts do not use default or weak credentials.
Promptly applying security updates can also prevent many ransomware attacks, as criminals cannot exploit known vulnerabilities. Additionally, regular backups are essential, because even if files are encrypted, organizations will still have access to them.
