Microsoft has flagged a new ransomware – which it calls Prestige – that is hitting transportation and logistics organizations in Ukraine and Poland.
See also: Police outsmarted the Deadbolt ransomware gang and got the decryption keys

See also: Phishing campaign spoofs Google Translate and steals your credentials
Microsoft has not seen the attackers use a specific software exploit, but all attacks use stolen Active Directory admin account credentials.
The ransom note identifies itself as “Prestige ransomware,” according to the Microsoft Threat Intelligence Center (MSTIC).
The Prestige ransomware was released on October 11th and stood out because enterprise-wide deployment of ransomware is not common in Ukraine and this activity was not linked to any of the 94 active ransomware groups that Microsoft tracks.
The activity also shares victimology with recent Russian state-aligned activity, especially in affected geographic regions and countries, and overlaps with previous victims of the FoxBlade malware (also known as HermeticWiper).
However, MSTIC says the Prestige campaign is separate from HermeticWiper, another destructive malware that has been deployed to multiple Ukrainian critical infrastructure operators over the past two weeks. Microsoft has been tracking malware deployed to Ukrainian since January.
MSTIC is tracking this activity as DEV-0960. DEV is its term for previously unknown threat actors.

The group uses several publicly available tools to execute remote code and gain highly privileged administrator credentials. But MSTIC does not know how the attackers initially gained access to the networks . It suspects that the attackers already had privileged credentials from previous compromises. In all cases, although the hackers gained access, they already had domain administrator privileges before deploying the ransomware.
See also: 45,000 VMware ESXi servers just reached their end-of-life
Microsoft describes three main methods the team used within an hour of each attack. The fact that they used multiple methods, rather than just one, was unusual.
"The threat landscape in Ukraine continues to evolve and destructive attacks are a consistent theme," Microsoft warned.
Information source: zdnet.com
