HomeSecurityThe new Rorschach ransomware is the fastest encryptor discovered so far...

New Rorschach ransomware is the fastest encryptor discovered so far

The Rorschach ransomware was recently discovered and is the fastest cryptojacking ransomware discovered to date – a game changer for cybersecurity!

Following a cyberattack on an American company, specialist malware researchers have identified what appears to be an unprecedented ransomware strain that stands out from the rest due to its “technically unique features” and have dubbed it Rorschach.

Tests conducted by researchers found that Rorschach is currently the fastest ransomware available, especially in terms of encryption speed.

After exploiting a vulnerability in the threat detection and incident response tool, the criminals unleashed their malware on the unfortunate victim's network - this was discovered by analysts.

Rorschach ransomware

Rorschach details

In response to an incident at a US-based company, Check Point experts revealed that Rorschach had been spread using the DLL side-loading technique through one of the signed components of Cortex XDR, Palo Alto Networks' extensive detection and response tool.

The attacker used the cy.exe version 7.3.0 from the Cortex XDR Dump Service Tool to deliver the Rorschach loader and the injector (winutils.dll) that triggered the ransomware payload, “config.ini” to the Notepad process in one swift move!

The payload file has UPX-type protection against analysis, while the main payload is protected from reverse engineering and detection through virtualization of parts of the code using VMProtect software.

According to Check Point's findings, when Rorschach is activated on a Windows Domain Controller, it will create a comprehensive group policy that can then be spread to other hosts in the domain.

After exploiting a system, the malware systematically erases its digital traces by deleting four event logs – Application, Security, System, and Windows Powershell.

New Rorschach ransomware is the fastest encryptor discovered so far

Rorschach comes armed with pre-programmed settings, but you can also unlock even more powerful features using command line arguments.

According to Check Point, the malicious code is so intricately hidden that it requires reverse engineering to fully reveal it.

The Rorschach encryption process

Rorschach will only start encrypting data when the system it is targeting is configured with a language that is not part of the Commonwealth of Independent States (CIS).

This encryption system is a combination of the curve25519 and eSTREAM cipher hc-128 algorithms and follows the trend of brute force. Instead of fully encrypting files, it provides partial protection, which ultimately significantly speeds up the calculation speed.

According to the researchers, the Rorschach encryption routine shows excellent ability to use input/output completion gates for efficient thread scheduling.

To measure the effectiveness of Rorschach encryption, Check Point put its speed to the test with an experiment using 220,000 files on a machine with 6 CPU.

Compared to LockBit v3.0, the fastest ransomware strain available, Rorschach managed to encrypt the data in an astonishing 4.5 minutes – a feat that took the superior variant 7 minutes of processing time!

After locking the system, a ransom note similar to those used by the Yanlowang ransomware appears.

As researchers discovered, a previous version of the malware had used a ransom message similar to the one later used by DarkSide.

According to Check Point, it appears that the similarity between Rorschach and DarkSide – an operation that was renamed BlackMatter in 2021 before mysteriously disappearing later that year – was likely what confused other researchers.

In November 2021, BlackMatter members joined forces to create the ALPHV/BlackCat ransomware operation.

According to Check Point, Rorschach has used the most effective features from popular ransomware strains available online, such as Babuk, LockBit v2.0, and DarkSide.

This malware not only spreads itself, but also significantly increases the risk of ransomware attacks.

At this time, the operators of the Rorschach ransomware remain unknown and there is no brand, which is rarely seen in the ransomware scene.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS