HomeSecurityRyuk ransomware: It takes 29 hours from sending an email to breaching systems

Ryuk ransomware: It takes 29 hours from sending an email to breaching systems

A attack took 29 hours from sending an email to a potential victim to fully breaching and encrypting systems, according to the DFIR Report, a project that provides threat intelligence from real-world attacks observed by honeypots .

Ryuk ransomware was initially thought to be the work of hackers due to its similarity to the “Hermes” ransomware, but was later linked to hackers in Russia. Over the past two years, Ryuk ransomware has been behind a number of high-profile attacks, including those targeting Pennsylvania-based Universal Health Services (UHS) and the Alabama-based DCH Regional Medical Center hospital system .

Ryuk ransomware

In the case of the attack observed by DFIR Report, it all started with a malicious email that carried a link to download the Bazar/Kegtap loader , which injected itself into multiple processes and performed reconnaissance on the infected system, using Windows utilities such as nltest and net group , as well as the third-party tool “AdFind” .

The malware remained silent for about a day, after which a second phase of reconnaissance was initiated, using the same tools, as well as Rubeus. The data was transferred to a remote server and the attackers performed a lateral move.
To compromise other systems on the network, the attackers used various methods, such as remote WMI (Windows Management Instrumentation), remote service execution with PowerShell, and a Cobalt Strike beacon “thrown” over SMB. The Cobalt Strike beacon was then used as the main focal point.

Ryuk ransomware

Additional beacons were then created throughout the environment and PowerShell was used to disable Windows Defender. The Ryuk ransomware was executed within a minute of being transferred via SMB from the hub, and once encryption began, the servers used to store backups were hit first.

The DFIR Report, which provides a comprehensive technical analysis of the attacks, reveals that the Ryuk ransomware was also delivered to other hosts on the network via SMB. Furthermore, according to the DFIR Report, in total, this campaign lasted 29 hours – from the initial execution of Bazar, to the domain-wide ransomware. If victims had missed the first day of discovery, they would have had just over 3 hours to respond before being asked for a ransom.

Ryuk ransomware

After encrypting the systems, the attackers demanded around 600 bitcoins (about $6 million) in ransom. However, they were willing to negotiate with the victims.

Yesterday, Microsoft announced that it had destroyed the infrastructure of TrickBot, the botnet that was used as the main delivery channel for the Ryuk ransomware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS