HomeSecurityRansomware groups automate payload distribution with SystemBC malware

Ransomware groups automate payload distribution with SystemBC malware

SystemBC , a malware sold on underground marketplaces, is used by ransomware- as -a-service (RaaS) businesses to hide malicious traffic and automate the delivery of the ransomware payload to victims' networks.

SystemBC

SystemBC was first detected in 2018 and was used in several 2019 campaigns as a “virtual private network.” The malware allowed ransomware gangs and their collaborators to deploy a persistent backdoor to systems victims’

This helped them create obfuscated communication channels for automated ransomware payload delivery and data.

SystemBC is used by Ryuk and the Egregor gang

Sophos researchers observed that the SystemBC malware had been deployed in all Ryuk and Egregor ransomware attacks over the past few months.

“ We are increasingly seeing ransomware operators deploying ransomware, using malware and other tools ,” Sophos security researcher Sean Gallagher said in a report .

“SystemBC is part of ransomware gangs' toolkits. Sophos has detected hundreds of attempts to deploy SystemBC in recent months“.

Researchers discovered that the Ryuk ransomware gang deploys SystemBC on the domain controller along with other malware, such as Buer Loader, BazarLoader , and Zloader, while Egregor operators use the Qbot information stealer.

Ransomware

Automatic ransomware payload deployment

Ransomware operators use this backdoor as a remote administration tool (RAT) along with the Cobalt Strike post-exploitation tool, after gaining access to victims' networks.

SystemBC also automates various tasks, such as deploying ransomware on target networks, after it has first stolen and removed information.

Finally, attackers use it to devices Windows, as well as to deliver malicious scripts, dynamic link libraries (DLLs), and scripts that execute automatically without requiring operator intervention.

These malware capabilities allow ransomware operators to carry out attacks that target multiple victims at a time.

Although some Windows anti-malware tools detect and block attempts to deploy the SystemBC malware, ransomware gangs can still install it on their targets' networks using legitimate credentials stolen in the early stages of attacks.

“The use of multiple tools in ransomware-as-a-service attacks creates an increasingly diverse attack profile that makes it difficult for security,” Gallagher said.

Strong security solutions, training , and constant vigilance are essential to counter such attacks.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS