HomeSecurityScarab ransomware: Distributed via Spacecolon toolset

Scarab ransomware: Distributed via Spacecolon toolset

Security researchers from ESET have discovered a malicious toolset named Spacecolon that is used to spread variants of the Scarab ransomware.

Space colon

According to the ESET report, the Spacecolon toolset is believed to gain access to organizational systems and networks through the exploitation of vulnerable web servers or through brute-force attacks on Remote Desktop Protocol (RDP) credentials.

Researchers say that some Spacecolon versions contain Turkish strings, suggesting the involvement of a Turkish-speaking developer.

See also: BlackCat ransomware gang hacked Seiko

Although the Spacecolon toolset has been around since at least May 2020, new campaigns are ongoing, with the most recent version being detected in May 2023. Despite extensive monitoring and analysis, ESET has yet to attribute the toolset’s use to any specific (known) hacking group. As a result, the company refers to the Spacecolon operators as “CosmicBeetle.”

Technically, the toolkit includes three main Delphi components: ScHackTool, ScInstaller, and ScService. These allow attackers to create remote access, develop additional tools, and even carry out attacks .

ScHackTool, acting as an orchestrator, manages the deployment of the two other components, ScInstaller and ScService. The sole purpose of ScInstaller is to install ScService, which acts as a backdoor, allowing hackers to execute commands, download malicious payloads, and retrieve system.

See also: New variant of BlackCat ransomware uses Impacket and RemCom tools

It is worth noting that in addition to these core components, the operators of the Spacecolon toolset also use a number of tools , both legitimate and malicious.

Scarab ransomware

ESET’s analysis also revealed the development of a new ransomware family, ScRansom, believed to be created by the developer behind Spacecolon. This new ransomware displays similar Turkish strings in its code, and similarities are also observed in the graphical user interface. Although it has not been observed in attacks, ESET suggests that ScRansom is still in its development stage.

See also: Cuba ransomware: Using Veeam exploit to attack critical infrastructure

More information about the Spacecolon toolset and its ties to the Scarab ransomware can be found in ESET's report

Cybercriminals are constantly evolving their techniques and using various tools that allow them to carry out more serious attacks with the aim of infecting systems with malware, locking users' files (ransomware) and stealing information. To protect yourself from such threats, update your systems regularlyto address potential vulnerabilities and use extra protection measures, such as two-factor authentication, creating backups ,using a reliable antivirus program, using a firewall, etc.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS