HomeSecurityFIN8: Uses a new version of the Sardonic backdoor to deliver...

FIN8: Uses a new version of the Sardonic backdoor to deliver BlackCat ransomware

The financial threat actor FIN8 has been observed using an updated version of a backdoor called Sardonic to deliver the BlackCat ransomware.

FIN8: Uses a new version of the Sardonic backdoor to deliver BlackCat ransomware

According to the Symantec Threat Hunter Team, which is owned by Broadcom, it was an attempt by the cybercrime group to diversify its focus and maximize its profits from infected entities. The attempted intrusion took place in December 2022.

The FIN8 group is being monitored by cybersecurity firm Syssphinx. Known to have been active since at least 2016, the adversary was initially attributed to attacks targeting point-of-sale (PoS) systems using malware such as PUNCHTRACK and BADHATCH.

The group resurfaced in March 2021 after more than a year with a revamped version of BADHATCH. This was followed by a completely new specialized implant called Sardonic, which was revealed by Bitdefender in August 2021.

See also: A Wisconsin county faces a serious ransomware attack

Unlike the previous variant, which was designed in C++, the latest iteration has significant changes, with most of the source code having been rewritten in C and modified to intentionally avoid similarities.

In the incident analyzed by Symantec, Sardonic is embedded in a PowerShell script that is deployed on the targeted system after initial access. The script is designed to launch a .NET loader, which then decrypts and executes an injector module for the final execution of the implant.

FIN8: Uses a new version of the Sardonic backdoor to deliver BlackCat ransomware

Sardonic supports up to 10 interactive sessions on an infected computer to execute malicious commands from a threat actor and also provides support for three different forms of add-ons to execute additional DLLs and shellcode.

Some of the backdoor's other features include the ability to drop arbitrary files and leak file contents from the compromised machine to an infrastructure controlled by an attacker.

This is not the first time FIN8 has been spotted using Sardonic in connection with a ransomware. In January 2022, Lodestone and Trend Micro uncovered FIN8's use of the Sardonic-based White Rabbit ransomware.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS