HomeSecurityCuba ransomware collaborates with Hancitor malware for spam attacks

Cuba ransomware collaborates with Hancitor malware for spam attacks

The Cuba Ransomware gang collaborated with the operators of the Hancitor malware to gain easier access to compromised corporate networks.

Cuba ransomware Hancitor malware

See also: QNAP warns of AgeLocker ransomware attacks on NAS devices

The Hancitor downloader (Chancitor) has been around since 2016, when Zscaler detected it distributing the Vawtrak credential-stealing Trojan. Since then, many campaigns have been detected over the years where Hancitor installs password-stealers, such as Pony, Ficker, and most recently, Cobalt Strike.

Hancitor is usually distributed through malicious spam campaigns that pretend to be DocuSign invoices, as you can see below.

Cuba ransomware collaborates with Hancitor malware for spam attacks

When a recipient clicks the “Sign document” link, it will download a malicious Word document that attempts to convince the target to disable protections.

Once the protections are disabled, malicious macros will be activated to download and install the Hancitor downloader.

See also: The Babuk ransomware gang stops its "operation"!

Just as Ryuk and Conti teamed up with TrickBot and Egregor and ProLock teamed up with QBot, so too does Cuba Ransomware team up with Hancitor to gain access to compromised networks.

Collaboration can accelerate attacks

Since its release in late 2019, the Cuba Ransomware has not been particularly active compared to other ransomware operations, such as REvil, Avaddon, Conti, and DoppelPaymer.

His most well-known attack was against ATFS, a widely used payment processor for local and state governments.

Since its attacks are now fueled by spam campaigns, we expect to see an increase in victims, and soon.

See also: Brazil: REvil ransomware targeted Rio Grande do Sul's judicial system

It should also be noted that while the Cuba Ransomware uses a photo of Fidel Castro and is named after the country of Cuba, its operators are based in Russia, according to cybersecurity firm Profero. This is a conclusion Profero came to after spotting the Russian language on the gang's data leak website.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS