A new strain of Thanos ransomware tries and fails to deliver a ransom note to compromised systems by overwriting the computers' Windows master boot record (MBR).
The new Windows Locker module has been discovered by security researchers at Palo Alto Networks, who analyzed two attacks and observed that Thanos ransomware successfully encrypted the devices of state-controlled organizations from the Middle East and North Africa in early July 2020.
“Replacing the MBR is a more destructive approach to ransomware than usual,” said Palo threat analyst Robert Falcone. “Victims will have to put in more effort to recover their files – even if they pay the ransom.”

“Fortunately, in this case, the code responsible for replacing the MBR caused a problem because the ransom message contained invalid characters, which left the MBR intact and allowed the system to boot properly.”
Similar behavior was previously exhibited by the Petya ransomware, when it was thought to replace the MBR of infected devices to display a ransom note that wouldn't leave the screen – effectively locking it there.
Although they failed to replace the MBRs of compromised computers, the Thanos ransomware operators continued to display ransom notes, creating text files called “HOW_TO_DECIPHER_FILES.txt” and asking victims to pay $20,000 to recover their data.
Researchers believe that the attackers gained access to the targeted networks before the payloads , as they were able to find valid credentials in the samples recovered after the attack.
The threat actors also used a layered approach to deliver the payloads, with custom PowerShell scripts, embedded C# code, and shellcode used to deliver the ransomware either locally or to other systems on the victims' networks using the stolen credentials mentioned above.
Palo has no information on whether state organizations from the Middle East and North Africa paid the attackers for their "efforts."
Thanos ransomware is a Ransomware-as-a-Service (RaaS) operation advertised on various Russian-speaking hacking forums since February 2020 that allows “contributors” to create custom ransomware payloads with the help of a builder provided by the ransomware developer.
Some Thanos samples have previously been flagged as Hakbit ransomware due to the different encryption used by RaaS partners, but Recorded Future Insikt Group says it is the same malware – after comparing the core functionality and code similarity.
Thanos is also the first ransomware to use the RIPlace evasion technique along with several other fairly advanced features designed to turn it into a serious threat, as it can steal files and simultaneously spread between various Windows devices using the PSExec program in conjunction with the SharpExec tool.
Three months ago, in June 2020, Thanos affiliates failed to convince several European companies from Austria, Switzerland, and Germany to pay the ransom they demanded after encrypting their systems.
