HomeSecurityRyuk ransomware gang: How did it earn $34 million from one victim?

Ryuk ransomware gang: How it earned $34 million from one victim?

One of the most notorious ransomware gangs, targeting large companies and organizations, managed to extort $34 million from a single victim in exchange for the decryption key that “liberated” their computers from ransomware. This achievement belongs to the hackers behind the Ryuk ransomware.

Ryuk ransomware

These hackers manage to breach corporate networks, spread to different devices , and cover their tracks before unleashing the Ryuk ransomware.

The group is also known as group “one” and is ruthless with victims . It often uses the Trickbot botnet in the first stage of the attack.

According to Vitali Kremez of Advanced Intelligence, recent victims of Ryuk group “one” include companies in the technology, healthcare, energy, financial services sectors. Government agencies.

Healthcare and social service organizations are one of the favorite targets of the Ryuk gang (13% of attacks).

Ryuk is one of the most popular ransomware. According to a report by Check Point, the gang carried out an average of 20 attacks per week during the third quarter of 2020.

Some of the gang's most recent victims include: Universal Health Services (UHS), Sopra Steria, law firm Seyfarth Shaw, furniture manufacturer Steelcase, and hospitals in Brooklyn and Vermont.

The researcher says that hackers are demanding an average of 48 bitcoins (nearly $750,000). It is said that during 2018, the criminals made at least $150 million.

Kremez published a report in which he states that the Russian ransomware gang is very tough in its negotiations and rarely shows leniency. The largest confirmed payment it received was 2,200 bitcoins, which is close to $34 million today.

Ryuk ransomware gang: How it earned $34 million from one victim?

15-step attack

Analyzing the attacks, Kremez notes that the Ryuk ransomware gang follows 15 steps to find available computers on the network, steal admin credentials , and deploy the Ryuk ransomware.

Hackers use software that is also used by red-teams to control network security :

  • Mimikatz: post-exploitation tool for stealing credentials from memory
  • PowerShell PowerSploit: a collection of PowerShell scripts
  • LaZagne: similar to Mimikatz, used to harvest passwords from locally stored software
  • AdFind: Active Directory query tool
  • Bloodhound: post-exploitation tool
  • PsExec: allows executing processes on remote systems

The attack chain begins by executing the Cobalt Strike “invoke” command to execute the “DACheck.ps1” script. In this way, the hackers check whether the current user is a member of a Domain Admin group.

From there, passwords are retrieved via Mimikatz, the network is mapped, and hosts are identified after scanning for FTP, SSH, SMB, RDP, and VNC protocols.

Here is the Ryuk ransomware gang's 15-step attack, according to Kremez:

  1. Domain admin check via the “Invoke-DACheck” script
  2. Collecting passwords via Mimikatz “mimikatz's sekurlsa::logonpasswords”
  3. Reset token and create token for administrative comment from Mimikatz command output
  4. Checking the network via “net view”
  5. Scan for FTP, SSH, SMB, RDP, VNC protocols
  6. Create a list for accessing available hosts
  7. Downloading the “AdFind” kit with the batch script “adf.bat” from “net view”
  8. Displaying the antivirus name via the “WMIC” command
  9. Download the “LaZagne” tool to scan the host computer
  10. Removing the tool
  11. Running ADFind and saving the outputs
  12. Delete AdFind and download the ouputs
  13. Granting access to Ryuk ransomware
  14. Downloading the remote execution software “PSExec” and uninstalling the antivirus
  15. Downloading batch scripts and executing Ryuk ransomware

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS