HomeSecurityNew Prestige ransomware affects organizations in Ukraine and Poland

New Prestige ransomware affects organizations in Ukraine and Poland

Microsoft has flagged a new ransomware – which it calls Prestige – that is hitting transportation and logistics organizations in Ukraine and Poland.

See also: Police outsmarted the Deadbolt ransomware gang and got the decryption keys

Prestige

See also: Phishing campaign spoofs Google Translate and steals your credentials

Microsoft has not seen the attackers use a specific software exploit, but all attacks use stolen Active Directory admin account credentials.

The ransom note identifies itself as “Prestige ransomware,” according to the Microsoft Threat Intelligence Center (MSTIC).

The Prestige ransomware was released on October 11th and stood out because enterprise-wide deployment of ransomware is not common in Ukraine and this activity was not linked to any of the 94 active ransomware groups that Microsoft tracks.

The activity also shares victimology with recent Russian state-aligned activity, especially in affected geographic regions and countries, and overlaps with previous victims of the FoxBlade malware (also known as HermeticWiper).

However, MSTIC says the Prestige campaign is separate from HermeticWiper, another destructive malware that has been deployed to multiple Ukrainian critical infrastructure operators over the past two weeks. Microsoft has been tracking malware deployed to Ukrainian since January.

MSTIC is tracking this activity as DEV-0960. DEV is its term for previously unknown threat actors.

New Prestige ransomware affects organizations in Ukraine and Poland

The group uses several publicly available tools to execute remote code and gain highly privileged administrator credentials. But MSTIC does not know how the attackers initially gained access to the networks . It suspects that the attackers already had privileged credentials from previous compromises. In all cases, although the hackers gained access, they already had domain administrator privileges before deploying the ransomware.

See also: 45,000 VMware ESXi servers just reached their end-of-life

Microsoft describes three main methods the team used within an hour of each attack. The fact that they used multiple methods, rather than just one, was unusual.

"The threat landscape in Ukraine continues to evolve and destructive attacks are a consistent theme," Microsoft warned.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS