A new ransomware named “White Rabbit” has emerged and according to recent research findings, it could be linked to the FIN8 hacking group.
The FIN8 group is a primarily financially motivated group that has been targeting financial institutions for several years, primarily through the development of POS malware that can steal credit card information.
See also: Moncler fashion brand: Data breach after ransomware attack

Double blackmail
The first public mention of the White Rabbit ransomware was in a tweet by ransomware expert Michael Gillespie.
In a new report from Trend Micro, researchers analyze a sample of the White Rabbit ransomware, which they obtained during an attack on a US bank in December 2021.
According to the researchers, the ransomware executable is a small payload (100 KB file) and requires entering a password to decrypt the malicious payload.
See also: Qlocker ransomware returns targeting QNAP NAS devices
The tactic of using a password to execute the malicious payload has been used in the past by other ransomware operations, including Egregor, MegaCortex, and SamSam.
Once executed with the correct password, the ransomware will scan all folders on the victim's device and encrypt files, while also creating ransom notes for each encrypted file.

The ransom note informs the victim that their files have been stolen and will be exposed if the ransom is not paid.
The victim is asked to pay the ransom within four days. After this short period, the White Rabbit ransomware operators threaten to send the stolen data to data protection authorities, leading to penalties for a GDPR data breach.
Evidence of the stolen files is uploaded to services such as 'paste[.]com' and 'file[.]io', while the victim is offered a live chat communication channel with the hackers, on a Tor negotiation site.
See also: Microsoft: Windows Server hotfixes for VPN errors
On the Tor site, the victim can view evidence of the stolen data. There is also a chat section where the victim can communicate with the attackers to negotiate the ransom.
Is White Rabbit ransomware linked to the FIN8 group?
According to Trend Micro, there is some evidence in the development stage of the ransomware that suggests there may be a connection to the FIN8 hacking group.
The new ransomware uses an unusual version of Badhatch (also known as “Sardonic”), a backdoor related to FIN8.

Researchers believe that White Rabbit is associated with the group because, typically, these hackers keep custom backdoors to themselves.
This finding is also confirmed by a different report on the same ransomware, by researchers at Lodestone. These researchers also found another commonality and commented that if there is no direct connection between this new ransomware and the group, then the ransomware may be mimicking the techniques of these hackers.
For now, White Rabbit has only targeted a few entities, but it is considered an emerging threat.
Source: Bleeping Computer
