HomeSecurityThe BlackCat ransomware group has upgraded its technique

The BlackCat ransomware group has upgraded its technique

The BlackCat ransomware group (also referred to as ALPHV) has emerged over the past 18 months, and new research reveals how a revamp of its technique earlier this year has made it an even more potent threat.

See also: New zero-day MOVEit Transfer is being exploited massively in data theft attacks

The BlackCat ransomware group has upgraded its technique

“BlackCat has become known as an extremely formidable and innovative ransomware operation since its debut in November 2021,” researchers from IBM Security X-Force said in an analysis of the group and its evolving malware published Tuesday.

"BlackCat is consistently listed in the top ten most active ransomware groups by multiple research entities and was linked in an FBI advisory in April 2022 to the now-defunct BlackMatter/DarkSide ransomware."

The Russia-based group and its affiliates have attempted extortion around the world and across multiple industries, sometimes pressuring victims into publishing sensitive stolen data, including financial and medical information.

In March, topless photos of breast cancer patients were published at Lehigh Valley Health Network after the organization refused to pay a $1.5 million ransom following an attack in February.

Since then, BlackCat's victims have included Western Digital, Sun Pharmaceuticals, and Constellation Software.

"Ransomware groups, like BlackCat, that are able to change their tools and trade tools to make their operations faster and more stealthy, have a better chance of extending their lifespan," IBM Security X-Force said in its post.

SC Media reported in May a finding by Trend Micro that BlackCat was using a new kernel driver that leveraged a separate user client executable to control, pause, and terminate various processes on the target endpoints of security agents deployed on protected computers.

See also: Exploit released for RCE flaw in popular ReportLab PDF library

BlackCat ransomware

This appears to be one of the features of a new version of its ransomware, called Sphynx, which the group pushed out in February. VX-Underground posted a screenshot of an announcement on Twitter, in which BlackCat said that its ransomware has been “completely rewritten from the ground up” and that “their main priority with this update was to optimize AV/EDR (anti-virus/endpoint detection and response) detection.”

In 2022, BlackCat switched to the Rust programming language , likely because it offered more opportunities to customize the malware and thwart detection and analysis efforts. In addition, the group's affiliates continued to exploit the functionality of Group Policy Objects (GPOs), both to develop tools and to circumvent security measures , according to the researchers.

See also: IT pros are overconfident about their ability to detect malware attacks

BlackCat attacks generally involved the deployment of tools for both encryption and data theft, as the group typically employed a dual extortion scheme.

In line with the more sophisticated tools being developed by other ransomware groups, X-Force said it expects BlackCat to continue to increase the speed and stealth of operations , using “new means to complete the various stages of its attacks.”

Source of information: scmagazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS