Russian hacktivists have used a new ransomware strain dubbed “Somnia” to encrypt the systems of several organizations in Ukraine.

The Computer Emergency Response Team of Ukraine (CERT-UA) reported the ransomware attacks and attributed them to the group 'From Russia with Love' (FRwL), also known as 'Z-Team'. CERT-UA is tracking it as UAC-0118.
In the past, this group had announced the creation of the Somnia ransomware on Telegram and had even published evidence of its attacks against targets located in Ukraine.
See also: Scam: Blackmailers target site owners and threaten to leak data
Ukraine has not confirmed any successful encryption attacks by the hacking group to date.
FRwL: Ransomware attack details
According to CERT-UA, the hacking group is using fake websites to imitate the “Advanced IP Scanner” software and trick employees of Ukrainian organizations into downloading an installer .
In reality, the installer infects the system with the Vidar stealer malware, which steals the victim's Telegram session data to take control of their account.
Then, according to CERT-UA, the attackers use the victim's Telegram account to connection data VPN.
If the VPN account does not have two-factor authentication, hackers can use it to gain unauthorized access to the compromised employee's corporate network.
See also: Phishing drops IceXLoader malware on thousands of devices
The attackers then install a Cobalt Strike beacon, steal data, and use Netscan, Rclone, Anydesk, and Ngrok for various remote access activities. Then, the Somnia ransomware is installed.
CERT-UA has stated that FRwL, with the help of origin access intermediaries, has carried out a series of attacks against Ukrainian organizations since early spring 2022.
The organization also noted that recent samples of the Somnia ransomware strain used AES, while previous versions used 3DES.
Somnia ransomware targets multiple file types. These include documents, images, databases ,archives, video files, and more. The creators of this strain clearly aim to cause as much destruction as possible.
The Ransomware adds the .somnia extension to a file name during the encryption process.
See also: Venus ransomware: Targets US healthcare organizations
The operators of Somnia ransomware primarily want to cause problems with the functioning of their targets, which is why they do not demand a ransom in exchange for a functional decryption tool.
Therefore, this malware may be considered more of a data wiper than a traditional ransomware.

Cyberwar between Russia and Ukraine
Since the war between Russia and Ukraine began, a cyberwar, with Russia constantly carrying out hacking attacks against Ukrainian organizations.
In turn, Ukraine has recruited hackers from various parts of the world to counter the attacks and launch other attacks against Russia.
Source: www.bleepingcomputer.com
