HomeSecuritySophos: Discovered new ransomware targeting Windows

Sophos: Discovered new ransomware targeting Windows

Security firm Sophos claims to have discovered a new ransomware targeting Windows systems. The ransomware is the final payload in an attack where the remaining stages are delivered via PowerShell scripts . Sophos principal researcher Andrew Brandt said in a detailed blog post that the new ransomware, codenamed Epsilon Red , is written in the Go programming language and was recently observed in an attack targeting a US company.

Epsilon Red ransomware Windows

According to Brandt, the hackers behind Epsilon Red have received approximately 4.29 bitcoins from at least one attacked entity (based on monitoring the bitcoin wallet provided by the attackers for the ransom payment).

“It appears that a corporate Microsoft Exchange server was the initial point of entry for gaining access to the corporate network,” he wrote.

See also: Zeppelin ransomware: Returns with updated versions!

“It is unclear whether this was triggered by the ProxyLogon exploit or another vulnerability, but it seems likely that the root cause was an unpatched server“.

Ransom note from Epsilon Red

According to the Sophos researcher, the ransom note left by the hackers is quite similar to the notes left by the Revil gang, which are however usually full of spelling and grammatical errors. In contrast, the Epsilon Red ransomware message has been modified so that the text is more readable for English-speaking users.

Many other researchers, in addition to Brandt, participated in examining the new Windows ransomware and writing the blog post: Anand Ajjan, Richard Cohen, Fraser Howard, Elida Leite, Mark Loman, Andrew Ludgate, Peter Mackenzie, Nirav Parekh, and Gabor Szappanos.

Mackenzie, director of Sophos' Rapid Response team , said: " Epsilon Red is an interesting new ransomware. The actual ransomware file is very limited, it has probably delegated other tasks, such as deleting backups, to PowerShell scripts ."

See also: FBI: Links Conti ransomware to 16 attacks on major US organizations

Sophos

“It is only used for file encryption and does not target anything in particular: if it decides to encrypt a folder, it will encrypt everything inside that folder. Unfortunately, this can mean that other executables and dynamic link libraries are encrypted as well. This can disable essential running programs or even the entire system. As a result, the attacked machine will have to be completely restored.“.

See also: Bose: Reveals data breach after ransomware attack!

"The best way to prevent ransomware like Epsilon Red from spreading is to ensure that servers are fully up-to-date and that your security solutions can detect and block any suspicious behavior and file encryption attempts," the researchers said.

Source: iTWire

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS