HomeSecurityNew Night Sky ransomware targets corporate networks

The new ransomware Night Sky targets corporate networks

The new year has arrived, and with it comes a new ransomware called "Night Sky" that targets corporate networks and steals data in double-jacking attacks.

The new ransomware Night Sky targets corporate networks

See also: FinalSite ransomware attack shuts down thousands of school websites

According to MalwareHunterteam, which first detected the new ransomware, Operation Night Sky began on December 27th and has since published the data of two victims.

One of the victims received an initial ransom demand of $800,000 to obtain a decryptor and prevent the stolen data from being published.

How Night Sky encrypts devices

A sample of the Night Sky ransomware seen by BleepingComputer has been customized to contain a personalized ransom note and encrypted login credentials to access the victim's trading page.

Upon launch, the ransomware will encrypt all files except those ending with the .dll or .exe file extensions.

When encrypting files, Night Sky will append the .nightsky extension to the encrypted file names, as shown in the image below.

Night Sky

In each folder, a ransom note named NightSkyReadMe.hta contains information related to what was stolen, a contact email, and hard coded credentials to the victim's negotiation page.

See also: The Lapsus$ ransomware gang “hit” the media company Impresa

The new ransomware Night Sky targets corporate networks

Instead of using a Tor website to communicate with victims, Night Sky uses email addresses and a clean website running Rocket.Chat. The credentials are used to connect to the Rocket.Chat URL provided in the ransom note.

The new ransomware Night Sky targets corporate networks

Double blackmail tactic

A common tactic used by ransomware operations is to steal unencrypted data from victims before encrypting devices on the network.

Threat actors then use this stolen data in a “double blackmail” strategy, where they threaten to leak the data if the ransom is not paid.

See also: AvosLocker ransomware hands over decryptor because it "hit" the police

To leak victims' data, Night Sky created a Tor that currently includes two victims, one from Bangladesh and another from Japan.

Night Sky

While there hasn't been a lot of activity with the new Night Sky ransomware feature, it's something to keep an eye on as we enter the new year.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS