CISA has published an analysis of the FiveHands ransomware recently discovered by FireEye’s Mandiant . In late April , researchers from FireEye’s Mandiant revealed that a sophisticated cybercrime gang tracked as “UNC2447” had exploited a zero-day vulnerability (CVE-2021-20016) in SonicWall Secure Mobile Access (SMA) devices , which was discovered earlier this year before the company had time to patch it.
UNC2447 has been targeting organizations in Europe and North Americausing a wide range of malware over the past few months. The malware used by the group since November 2020 includes Sombrat, FiveHands, the Warprism PowerShell dropper, the Cobalt Strike beacon, and FoxGrabber. During the extortion activity, UNC2447 used the FiveHands ransomware, with cybercriminals threatening victims with exposing their hack to the media or selling their data on hacking forums.
Read also: Ransomware group exploits SonicWall zero-day to compromise networks

The malware analysis report (MAR) published by CISA includes a detailed analysis of 18 malicious files submitted to the organization. One of the files is a new ransomware strain, eight files are open-source penetration testing tools and exploit kits referred to as FiveHands, and the files are related to the SombRAT RAT.
CISA discovered a recent successful cyberattack against an organization that used FiveHands ransomware, SombRAT, and open source tools to steal information and files, and then demand a ransom.
The MAR includes recommended response actions and recommended mitigation techniques to mitigate the risk of cyberattacks.
See also: Cuba ransomware collaborates with Hancitor malware for spam attacks

FiveHands ransomware also encrypts files in the recovery folder at C:\Recovery, and then writes a ransom note to every folder and directory on the system, named “read_me_unlock.txt”. Hackers use SombRAT as part of the attack, to download and execute additional malicious payloads.
Suggestion: QNAP warns of AgeLocker ransomware attacks on NAS devices
FiveHands ransomware uses a public key encryption program called “NTRUEncrypt”, enumerates Volume Shadow Copies with Windows Management Instrumentation (WMI) before deleting them, to make data. Finally, FiveHands ransomware is written in C++, and has many similarities to DeathRansom – both malware strains appear to be linked to HelloKitty ransomware.
Information source: securityaffairs.co
