HomeSecurityDarkSide: New ransomware earns millions of dollars

DarkSide: New ransomware earns millions of dollars

A new ransomware called DarkSide began attacking organizations earlier this month. Its customized attacks have already earned millions of dollars.

Since August 10, 2020, the new ransomware operation began carrying out targeted attacks against multiple companies.

In a “press release” issued by the hackers, they claim to be former associates who had made millions of dollars working with other ransomware operations.

After not finding a “product” that suited needs , they decided to start their own business.

Darkside

“We are a new product on the market, but that doesn’t mean we don’t have experience and came from nowhere. We have made millions of dollars in profits by partnering with other well-known crypto traders. We created DarkSide because we couldn’t find the perfect product for us. Now we have it.”

DarkSide states that they only target companies that can pay the specified ransom as they do not “want to kill business .”

Threat actors also stated that they do not target the following types of organizations.

  • Medical (hospitals).
  • Education (schools, universities).
  • Non-profit organizations.
  • Government sector.

It is too early to know whether they will follow through on this statement.

DarkSide ransom demands range from $200,000 to $2,000,000. These numbers may vary slightly depending on the victim.

At least one of the victims identified by BleepingComputer appears to have paid a ransom of one million dollars.

DarkSide steals data before encrypting victims

Like other ransomware attacks that operate manually, when DarkSide operators compromise a network, they will spread laterally across a network until they gain access to an admin account and the Windows domain controller.

While spreading laterally, attackers will collect unencrypted data from the victim's servers and upload it to their own devices.

This stolen data is then posted on a data leak website under control and used as part of the blackmail attempt.

When data is posted on the leak website, threat actors will list the name of the company, the date breach , how much data was stolen, screenshots of the data , and the types of data stolen.

DarkSide states that if a victim does not pay, it will publish all data on its website for at least six months. This extortion strategy is designed to scare a victim into paying the ransom.

If a victim pays the ransom, DarkSide states that it will remove the stolen data from website .

For victims who have already paid the ransom, their data has already been removed from the website.

Custom ransomware attacks

When executing the attacks, DarkSide will create a customized ransomware executable for the specific company being attacked.

When executed, the ransomware will execute a PowerShell command that deletes Shadow Volume Copies on the system so that they cannot be used to restore files.

According to Vitali Kremez of Advanced Intel, it then proceeds to shut down various databases, office applications, and email clients to prepare the computer for encryption.

When encrypting a computer, DarkSide will avoid terminating certain processes.

Specifically, TeamViewer is used for remote access to computers.

At the moment, there seems to be no way to recover the files for free.

Possible connection to REvil

During the analysis of DarkSide, it was discovered that it has some similarities to the REvil ransomware.

The most obvious similarity is the ransom notes which use almost the same template, as seen in the REVIL ransomware note below.

Darkside

In behavioral analysis of DarkSide, it was observed to execute a coded PowerShell script when it was first run.

DarkSide: New ransomware earns millions of dollars

When disabled, we can see that this PowerShell command is used to delete Shadow Volume Copies on the machine before encryption.

DarkSide: New ransomware earns millions of dollars

Using PowerShell to execute the above command is the same method used by REvil.

Finally, MalwareHunterTeam found that DarkSide intentionally avoids infecting victims in CIS countries. The code to do this is similar to that used in REvil and also in GandCrab.

Darkside
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS