Security researchers from ESET have discovered a malicious toolset named Spacecolon that is used to spread variants of the Scarab ransomware.

According to the ESET report, the Spacecolon toolset is believed to gain access to organizational systems and networks through the exploitation of vulnerable web servers or through brute-force attacks on Remote Desktop Protocol (RDP) credentials.
Researchers say that some Spacecolon versions contain Turkish strings, suggesting the involvement of a Turkish-speaking developer.
See also: BlackCat ransomware gang hacked Seiko
Although the Spacecolon toolset has been around since at least May 2020, new campaigns are ongoing, with the most recent version being detected in May 2023. Despite extensive monitoring and analysis, ESET has yet to attribute the toolset’s use to any specific (known) hacking group. As a result, the company refers to the Spacecolon operators as “CosmicBeetle.”
Technically, the toolkit includes three main Delphi components: ScHackTool, ScInstaller, and ScService. These allow attackers to create remote access, develop additional tools, and even carry out attacks .
ScHackTool, acting as an orchestrator, manages the deployment of the two other components, ScInstaller and ScService. The sole purpose of ScInstaller is to install ScService, which acts as a backdoor, allowing hackers to execute commands, download malicious payloads, and retrieve system.
See also: New variant of BlackCat ransomware uses Impacket and RemCom tools
It is worth noting that in addition to these core components, the operators of the Spacecolon toolset also use a number of tools , both legitimate and malicious.

ESET’s analysis also revealed the development of a new ransomware family, ScRansom, believed to be created by the developer behind Spacecolon. This new ransomware displays similar Turkish strings in its code, and similarities are also observed in the graphical user interface. Although it has not been observed in attacks, ESET suggests that ScRansom is still in its development stage.
See also: Cuba ransomware: Using Veeam exploit to attack critical infrastructure
More information about the Spacecolon toolset and its ties to the Scarab ransomware can be found in ESET's report
Cybercriminals are constantly evolving their techniques and using various tools that allow them to carry out more serious attacks with the aim of infecting systems with malware, locking users' files (ransomware) and stealing information. To protect yourself from such threats, update your systems regularlyto address potential vulnerabilities and use extra protection measures, such as two-factor authentication, creating backups ,using a reliable antivirus program, using a firewall, etc.
Source: www.infosecurity-magazine.com
