
Microsoft has discovered a new version of the BlackCat ransomware that integrates the Impacket networking framework and the Remcom hacking tool, which allow lateral spread across a compromised network.
See also: BlackCat: New extortion strategy adds data leakage API
In April, cybersecurity researcher VX-Underground tweeted about a new version of the BlackCat/ALPHV cipher called Sphynx.
“We are pleased to inform you that the testing of the basic features of ALPHV/BlackCat 2.0: Sphynx has been completed,” the BlackCat operators said in a message to their partners.
“The code, including encryption, has been completely rewritten from scratch. By default, all files are frozen. The main priority of this update was to optimize detection by AV/EDRs,” the ransomware.
Shortly after, IBM Security X-Force conducted a deep dive into the new BlackCat cryptogram, warning that the cryptogram had evolved into a toolkit.
This was based on strings in the executable file that indicated it contained impacket, which is used for post-exploit operations such as remote execution and dropping secrets from processes.

The BlackCat Sphynx Cryptographer
In a series of posts today, Microsoft's Threat Intelligence team says it also analyzed the new version of Sphynx and found that it used the Impacket framework to spread laterally across compromised networks.
"Microsoft has observed a new variant of the BlackCat ransomware being used in recent campaigns," Microsoft.
“This release includes the open source communication framework tool Impacket, which attackers use to facilitate lateral movement into target environments.”
Impacket is described as a collection of open source Python classes for working with network protocols.
However, it is more commonly used as a post-exploitation toolkit by penetration testers, red teamers, and attackers to laterally spread across a network, dump credentials from processes, perform NTLM relay attacks, and more.
Impacket has become very popular among hackers who compromise a device on a network and then use the framework to gain elevated credentials and gain access to other devices.
Proposal: FIN8: Uses a new version of the Sardonic backdoor to deliver BlackCat ransomware
According to Microsoft, the BlackCat operation uses the Impacket framework to copy credentials and execute remote services to deploy the cryptographer across the network.
In addition to Impacket, Microsoft says the cryptographer integrates the Remcom hacking tool, which is a small remote shell that allows the cryptographer to remotely execute commands on other devices on a network.
In a private Microsoft 365 Defender Threat Analytics advisory seen by BleepingComputer, Microsoft says it saw this new cipher used by BlackCat affiliate “Storm-0875” since July 2023.
Microsoft identifies this new version as BlackCat 3.0, although, as we said earlier, the ransomware enterprise calls it 'Sphynx' or 'BlackCat/ALPHV 2.0' in communications with its affiliates.

An ever-evolving ransomware gang
BlackCat, or ALPHV, began its operations in November 2021 and is believed to be an evolution of the DarkSide/BlackMatter gang, which was responsible for the attack on the Colonial Pipeline.
The ransomware gang has always been considered one of the most advanced and leading ransomware operations, constantly evolving its operation with new tactics.
For example, as a new extortion tactic last summer, the ransomware gang created a clearweb website dedicated to leaking data for a specific victim so that customers and employees could check if their data was exposed.
More recently, the perpetrators created a data leakage API, allowing for easier dissemination of stolen data.
With the BlackCat cryptographer evolving from a decryptor to a full post-exploit toolkit, it allows ransomware partners to more quickly deploy file encryption across the network
Since it is crucial to detect ransomware attacks as soon as they occur, the addition of these tools makes it difficult for defense actors.
Read also: BlackCat ransomware: Promotes Cobalt Strike via WinSCP search ads
source of information:bleepingcomputer.com
