Cybersecurity researchers are reporting increased activity of Hello XD ransomware, whose operators are now developing an upgraded sample that features stronger encryption.

HelloXD is a ransomware family that performs dual extortion attacks that emerged in November 2021. During Unit 42’s research, several variants were observed affecting Windows and Linux systems. Unlike other ransomware groups, this ransomware family does not have an active leak website. Instead, it prefers to direct the affected victim to negotiations via TOX chats and onion-based messenger instances.
See also: Is the Vice Society ransomware gang behind the Palermo attack?
This particular family, first identified in November 2021, was based on leaked Babuk source code and was involved in a small number of double-ransomware attacks, where threat actors stole corporate data before encrypting devices.
According to a new report from Palo Alto Networks Unit 42, the malware author created a new encryptor that features custom packing to avoid detection and changes to the encryption algorithm.
This marks a significant departure from the Babuk code and underscores the author's intent to develop a new ransomware strain with unique capabilities and features for increased attacks.
Hello XD ransomware operation
The Hello XD ransomware operation does not currently use a Tor to extort victims, but instead directs victims to initiate negotiations directly through a TOX chat service.
In the latest version, the malware operators have added an onion site link to the dropped ransom note, but Unit 42 says the site is offline, so it may be under construction.

When executed, Hello XD attempts to disable shadow copies to prevent easy system recovery, and then encrypts files, adding the .hello extension to the filenames.
See also: Ransomware sells its decryptor on the Roblox Game Pass store
In addition to the ransomware payload, Unit 42 also observed Hello XD operators now using an open-source backdoor called MicroBackdoor to navigate the compromised system, extract files, execute commands, and delete traces.
This MicroBackdoor executable is encrypted using the WinCrypt API and is embedded in the ransomware payload, so it is “dropped” into the system immediately after infection.

Crypter and encryption
The custom packaging program deployed in the second version of the ransomware payload features two layers of obfuscation.
The author extracted the encryption by modifying UPX, an open-source packer program that many malware creators have widely abused in the past.

Decrypting the embedded blobs involves using a custom algorithm that contains unusual instructions like XLAT, while the API calls in the wrapper are surprisingly not obfuscated.
The most interesting aspect of the second major release of Hello XD is the change of the encryption algorithm from the modified HC-128 and Curve25519-Donna to Rabbit Cipher and Curve25519-Donna.

Additionally, the file marker in the second version was changed from a coherent string to random bytes, making the cryptographic result stronger.
See also: Cuba ransomware: New variant detected in recent attacks
What to expect
Hello XD is currently a dangerous early-stage ransomware project currently being used by hackers. Although its infection volumes are not yet significant, its active and targeted development sets the stage for a more dangerous situation.
Unit 42 traced its origins to a Russian-speaking threat actor using the alias X4KME, who uploaded tutorials on deploying Cobalt Strike Beacons and malicious infrastructure online.

Additionally, the same hacker has posted on forums to offer proof-of-concept (PoC) exploits, encryption services , custom Kali Linux distributions , and malware-hosting and distribution services.
Overall, this threat actor appears to have knowledge and is able to advance Hello XD, so analysts should closely monitor its development.
Information source: bleepingcomputer.com
