HomeSecurityEgregor ransomware: It is becoming increasingly dangerous following in the footsteps of Maze

Egregor ransomware: It is becoming increasingly dangerous, following in the footsteps of Maze

Security experts are warning that a new ransomware group is rapidly escalating its threat activity, carrying out double extortion attacks on numerous victims around the world. This is the Egregor ransomware gang, which became known after attacking Barnes & Noble and game developers Ubisoft and Crytek in October, Digital Shadows reports . The Egregor gang is believed to be the successor to the Maze ransomware gang.

However, the group has been active in the threat landscape since September, carrying out attacks targeting 15 different victims. Subsequently, there was a 240% increase, with over 50 organizations being added to its victim list. It is worth noting that since November 17, 21 more victims have been added.

According to Digital Shadows, victims of Egregor ransomware include organizations operating in the industrial goods and services sector (38%), with the majority of them (83%) located in the US.

Additionally, the malware is designed with multiple built-in anti-analysis measures, such as code obfuscation and packed payloads. Specifically, Digital Shadows noted that Windows application programming interfaces (APIs) are leveraged to encrypt payload data . If security teams cannot present the correct command line argument, then the data cannot be decrypted and the malware cannot be analyzed.

ransomware

The company further added that when presented with the correct command line argument, the malware executes by entering the iexplore.exe, encrypting all text files and documents and attaching a ransom note to each folder that has an encrypted file. This process includes files on remote computers and servers via checks in LogMeIn event logs.

The hackers , like other gangs, maintain a dark site where they publish the data they steal from their victims, so that the latter can be forced to pay a ransom. As reported by Infosecurity Magazine, the Egregor gang appears to be following in the footsteps of the Maze ransomware gang, which ceased operations in October.

Maze ransomware

For example, she posted 200MB of data concerning Ubisoft games, claiming she had in her possession the source code of the unreleased game Watchdogs: Legion. At the same time, 400MB of data related to Crytek's Warface and Arena of Fate games were stolen.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS