HomeSecuritySnapMC hackers: They skip encryption and simply steal files

SnapMC hackers: They skip encryption and just steal files

A new malicious group identified as SnapMChas emerged in the cybercrime scene, performing the typical data theft with extortion that supports ransomware, but without encrypting files.

SnapMC

See also: New Python ransomware: Encrypts system within three hours

File encryption is considered a key component of ransomware attacks, as it is the element that puts the most pressure on the victim.

The theft of data for double blackmail purposes came later as an additional form of pressure on the victim, but it always took a back seat to the chaos that encrypting a network could cause.

Soon, ransomware attackers realized the power of this approach, as many companies could restore corrupted files from backups, but could not restore stolen files and their consequences.

Researchers at NCC Group are tracking a new adversary they call SnapMC, named after the group's method of breaking into networks, stealing files, and delivering ransom messages in less than 30 minutes.

The SnapMC gang uses the Acunetixto identify a series of flaws in a target's VPN and web server applications, and then successfully exploits them to breach the corporate network.

The most exploited flaws observed in the malicious agent's initial access attempts include PrintNightmare LPE, remote code execution in Telerik UI for ASPX.NET, as well as various SQL injection attacks.

See also: Ransomware operators arrested in Ukraine

The actors use SQL database extraction scripts to steal the data, while the CSV files are compressed with the 7zip archive utility before infiltration. Once everything is sorted, the MinIO client is used to send the data back to the attacker.

hackers

Considering that SnapMC exploits known vulnerabilities that have already been patched, updating your software tools would be a good way to protect yourself from this growing threat.

As the NCC team points out in report , even if an organization is using a vulnerable version of Telerik, placing it behind a well-configured Web Application Firewall would render any exploitation attempts futile.

In data extortion attacks, meeting the threat actor's demands by paying ransomware guarantees nothing. On the contrary, it could give hackers an incentive to attempt further extortion in the future.

It is also possible that even if a victim pays the ransom, their data may end up being sold on criminal marketplaces or forums as an additional way of generating revenue for the attackers.

Ransomware negotiation firm Coveware strongly advises its customers to never pay ransom to prevent stolen files from being leaked to the public.

See also: HSE attack: Hackers provide decryption tool, but threaten data leak

During negotiated cases in the past, victims paid ransom and their data was leaked or never given proof of deletion.

Because of this, victims must automatically assume that their data has been shared with other threat actors and will be used or leaked in the future, regardless of whether they paid a ransom.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS