The new RansomBoggs ransomware wreaking havoc on systems in Ukraine and detected this week is linked to the Russian military threat group Sandworm.
See also: UK: Bans use of Chinese Hikvision surveillance cameras on govt sites

According to Slovak software company ESET, ransomware called RansomBoggs was discovered on multiple networks of Ukrainian organizations.
ESET Research Labs said that although the malware is new, its development mirrors previous attacks linked to Sandworm.
The attack used a PowerShell script to distribute .NET ransomware from the domain controller, which is almost identical to what was observed last April during the Industroyer2 attacks against the energy sector.
The PowerShell script behind the RansomBoggs payloads is known as POWERGAP. In March, the same script was used to deliver the devastating CaddyWiper in attacks against Ukrainian organizations.
See also: Twitter: Data of millions of users is available for free
Once RansomBoggs infiltrates the victim's network, it encrypts files using AES-256 in CBC mode with a random key (which is randomly generated, encrypted with RSA, and written to aes.bin). Additionally, each encrypted file will have the .chsch extension appended to its original extension.
The RSA public key may be written into the malware itself or provided as an argument, depending on the variant used in the attack.
The ransomware also drops ransom notes impersonating James P. Sullivan, the main character of the film Monsters Inc, with references to the film's code found within the malware.
Earlier this month, Microsoft linked the cyberespionage group Sandworm (tracked by the company as IRIDIUM) to the Prestige ransomware attacks. These attacks have been targeting transportation and logistics companies in Ukraine and Poland since October.
In February, a security advisory issued jointly by US and UK also attributed the Cyclops Blink botnet to the Russian military threat group, before it was prevented from being used again by hackers.
Sandworm is an elite group of Russian hackers that has been active for at least two decades. They are believed to belong to Unit 74455 of the Main Center for Special Technologies (GTsST) of the Russian GRU.
See also: Report: Data of millions of WhatsApp users is being sold
They have previously been linked to attacks that led to the KillDisk wiper attacks targeting banks in Ukraine. Sandworm is also believed to be behind the development of the NotPetya ransomware, which has caused billions of dollars in damage since June 2017.
Information source: bleepingcomputer.com
