HomeSecurityDonut: The extortion gang now has its own ransomware

Donut: The extortion gang now has its own ransomware

It has been confirmed that the Donut extortion gang is now also deploying ransomware on corporate networks.

Donut ransomware

According to BleepingComputer, the Donut first came to light in August, after it had attacked Greek natural gas company DESFA, British architecture firm Sheppard Robson , and multinational construction company Sando.

The data for Sando and DESFA appears to have been published on various data leak sites associated with ransomware operations. Sando's data was found on the Hive ransomware site and DESFA 's on the Ragnar Locker site .

See also: Hive ransomware: Extorted over 100 million

Doel Santos, a researcher at Unit 42, also noticed that the TOX ID used in the ransom notes was observed in samples of the HelloXD ransomware.

The publication of the stolen data on various sites leads us to the conclusion that the Donut extortion gang is an associate of several ransomware operations and is now trying to utilize the data in its own ransomware operation.

Donut ransomware

According to BleepingComputer, a sample of a cryptojacking tool VirusTotalused by the Donut operation . This suggests that the group is using its own custom ransomware to carry out double-extortion attacks.

The ransomware is under analysis. However, we know that when it executes, it scans and encrypts files with specific extensions. When encrypting files, it avoids files and folders that contain the following strings:

Donut: The extortion gang now has its own ransomware

Donut ransomware encrypts files by appending the .d0nut extension.

See also: AXLoker ransomware: Hacks Discord accounts

The Donut Gang uses interesting graphics, a bit of humor , and even offers a builder for an executable that acts as a gateway to the Tor data leak website (see below)

For example, in a ransom note seen by BleepingComputer, next to the text with the attack information, there is a spinning donut.

Donut: The extortion gang now has its own ransomware

Another note initially appeared as a command prompt displaying a PowerShell error, which then gradually displayed a ransom with interesting graphics, once again.

Ransom notes are obfuscated to make them difficult to detect.

The ransom notes for the new Donut ransomware give various options for victims to contact the criminals, such as TOX and a Tor trading site.

The Donut ransomware operation also includes a data leak site “builder” consisting of a bash script to create a Windows and Linux Electron app with a bundled Tor client to access their data leak sites.

See also: 2022: One-third of organizations worldwide have been breached at least 7 times

This application is currently “broken” as it uses HTTPS URLs, which are not currently functional.

The above shows that the Donut extortion gang is constantly evolving, as it now uses its own ransomware.

Ransomware attacks are becoming more common, so it's important for businesses to take steps to protect themselves. By training employees on cybersecurity best practices, implementing a robust backup solution , and keeping software up to date security, you can help reduce the chances of falling victim to a ransomware attack.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS